6.5

CVE-2018-1775

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.

Data is provided by the National Vulnerability Database (NVD)
IbmSpectrum Virtualize Software Version >= 7.5 <= 8.2
   IbmFlashsystem V9000 Version-
   IbmFlashsystem V9100 Version-
   IbmSan Volume Controller Version-
   IbmStorwize V3500 Version-
   IbmStorwize V3700 Version-
   IbmStorwize V5000 Version-
   IbmStorwize V7000 Version-
IbmSpectrum Virtualize Software For Public Cloud Version >= 7.5 <= 8.2
   IbmFlashsystem V9000 Version-
   IbmFlashsystem V9100 Version-
   IbmSan Volume Controller Version-
   IbmStorwize V3500 Version-
   IbmStorwize V3700 Version-
   IbmStorwize V5000 Version-
   IbmStorwize V7000 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.46% 0.631
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
psirt@us.ibm.com 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.