Vulnerability Description
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DLSnap could allow an unauthenticated attacker to read arbitrary files on the system. IBM X-Force ID: 139566.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Storwize V7000 Firmware | >= 6.1.0.0, < 7.5.0.14 |
| Ibm | Storwize V7000 | - |
| Ibm | Storwize V5000 Firmware | >= 6.1.0.0, < 7.5.0.14 |
| Ibm | Storwize V5000 | - |
| Ibm | Storwize V3700 Firmware | >= 6.1.0.0, < 7.5.0.14 |
| Ibm | Storwize V3700 | - |
| Ibm | Storwize V3500 Firmware | >= 6.1.0.0, < 7.5.0.14 |
| Ibm | Storwize V3500 | - |
| Ibm | Storwize V9000 Firmware | >= 6.1.0.0, < 7.5.0.14 |
| Ibm | Storwize V9000 | - |
| Ibm | San Volume Controller Firmware | >= 6.1.0.0, < 7.5.0.14 |
| Ibm | San Volume Controller | - |
| Ibm | Spectrum Virtualize | >= 6.1.0.0, < 7.5.0.14 |
| Ibm | Spectrum Virtualize For Public Cloud | >= 6.1.0.0, < 7.5.0.14 |
Related Weaknesses (CWE)
References
- http://www.ibm.com/support/docview.wss?uid=ssg1S1012263Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ssg1S1012282Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ssg1S1012283Vendor Advisory
- http://www.securityfocus.com/bid/104349Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/139566VDB EntryVendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ssg1S1012263Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ssg1S1012282Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ssg1S1012283Vendor Advisory
- http://www.securityfocus.com/bid/104349Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/139566VDB EntryVendor Advisory
FAQ
What is CVE-2018-1438?
CVE-2018-1438 is a vulnerability with a CVSS score of 7.5 (HIGH). IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web han...
How severe is CVE-2018-1438?
CVE-2018-1438 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1438?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Storwize V7000 Firmware, Ibm Storwize V7000, Ibm Storwize V5000 Firmware, Ibm Storwize V5000, Ibm Storwize V3700 Firmware.