Lucene search

K
cvelistIbmCVELIST:CVE-2023-47715
HistoryMar 21, 2024 - 2:10 p.m.

CVE-2023-47715 IBM Storage Protect Plus Server improper access control

2024-03-2114:10:59
CWE-269
ibm
www.cve.org
3
ibm
storage protect plus
server
authenticated user
hypervisor configuration
modify

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

4.6

Confidence

High

EPSS

0

Percentile

13.1%

IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. IBM X-Force ID: 271538.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Storage Protect Plus Server",
    "vendor": "IBM",
    "versions": [
      {
        "lessThanOrEqual": "10.1.16",
        "status": "affected",
        "version": "10.1.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

4.6

Confidence

High

EPSS

0

Percentile

13.1%

Related for CVELIST:CVE-2023-47715