6.5

CVE-2023-46170

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily read files after enumerating file names.

Data is provided by the National Vulnerability Database (NVD)
IbmDs8900f Firmware Version89.22.19.0
   IbmDs8900f Version-
IbmDs8900f Firmware Version89.30.68.0
   IbmDs8900f Version-
IbmDs8900f Firmware Version89.32.40.0
   IbmDs8900f Version-
IbmDs8900f Firmware Version89.33.48.0
   IbmDs8900f Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.157
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@us.ibm.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-204 Observable Response Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.