Lucene search

K
cveIbmCVE-2014-3077
HistorySep 15, 2014 - 2:55 p.m.

CVE-2014-3077

2014-09-1514:55:11
CWE-200
ibm
web.nvd.nist.gov
26
ibm
sonas
system storage
storwize
v7000 unified
v7000u
security
vulnerability
audit log
sensitive information
local users

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.7

Confidence

Low

EPSS

0

Percentile

5.1%

IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.

Affected configurations

Nvd
Node
ibmstorwize_v7000_unified_softwareMatch1.3.0.0
OR
ibmstorwize_v7000_unified_softwareMatch1.3.2.0
OR
ibmstorwize_v7000_unified_softwareMatch1.3.2.3
OR
ibmstorwize_v7000_unified_softwareMatch1.4.0.0
OR
ibmstorwize_v7000_unified_softwareMatch1.4.0.4
OR
ibmstorwize_v7000_unified_softwareMatch1.4.1.0
OR
ibmstorwize_v7000_unified_softwareMatch1.4.1.1
OR
ibmstorwize_v7000_unified_softwareMatch1.4.2.0
OR
ibmstorwize_v7000_unified_softwareMatch1.4.3.0
OR
ibmstorwize_v7000_unified_softwareMatch1.4.3.3
AND
ibmstorwize_unified_v7000Match-
VendorProductVersionCPE
ibmstorwize_v7000_unified_software1.3.0.0cpe:2.3:a:ibm:storwize_v7000_unified_software:1.3.0.0:*:*:*:*:*:*:*
ibmstorwize_v7000_unified_software1.3.2.0cpe:2.3:a:ibm:storwize_v7000_unified_software:1.3.2.0:*:*:*:*:*:*:*
ibmstorwize_v7000_unified_software1.3.2.3cpe:2.3:a:ibm:storwize_v7000_unified_software:1.3.2.3:*:*:*:*:*:*:*
ibmstorwize_v7000_unified_software1.4.0.0cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.0.0:*:*:*:*:*:*:*
ibmstorwize_v7000_unified_software1.4.0.4cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.0.4:*:*:*:*:*:*:*
ibmstorwize_v7000_unified_software1.4.1.0cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.1.0:*:*:*:*:*:*:*
ibmstorwize_v7000_unified_software1.4.1.1cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.1.1:*:*:*:*:*:*:*
ibmstorwize_v7000_unified_software1.4.2.0cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.2.0:*:*:*:*:*:*:*
ibmstorwize_v7000_unified_software1.4.3.0cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.3.0:*:*:*:*:*:*:*
ibmstorwize_v7000_unified_software1.4.3.3cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.3.3:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.7

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2014-3077