Lucene search

K
ibmIBM5CA6078717CDD955706DD9AFC0D24AC2A4BB77B8BED2CAB55C6C16EE70E7B3C8
HistoryApr 10, 2024 - 9:28 p.m.

Security Bulletin: Improper integrity checking might affect IBM Storage Defender – Resiliency Service (CVE-2024-27261)

2024-04-1021:28:57
www.ibm.com
11
ibm
storage defender
resiliency service
cve-2024-27261
data integrity
vulnerability
connection manager
upgrade

CVSS3

6.4

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

9.0%

Summary

IBM Storage Defender – Resiliency Service is vulnerable and that can result in data integrity issues. The vulnerabilities have been addressed.

Vulnerability Details

CVEID:CVE-2024-27261
**DESCRIPTION:**IBM Storage Defender - Resiliency Service could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed.
CVSS Base score: 6.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/283986 for the current score.
CVSS Vector: (CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Storage Defender - Resiliency Service 2.0.0-2.0.2

Remediation/Fixes

The Connection Manager included with Defender 2.0.3 and newer provides the fixes. If using a version of the Connection Manager obtained from Defender 2.0.0 - 2.0.2 IBM strongly recommends upgrading. Instructions for upgrading can be found here.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmstorage_defenderMatch2.0.3
VendorProductVersionCPE
ibmstorage_defender2.0.3cpe:2.3:a:ibm:storage_defender:2.0.3:*:*:*:*:*:*:*

CVSS3

6.4

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

9.0%

Related for 5CA6078717CDD955706DD9AFC0D24AC2A4BB77B8BED2CAB55C6C16EE70E7B3C8