Lucene search

K
vulnrichmentIbmVULNRICHMENT:CVE-2023-47715
HistoryMar 21, 2024 - 2:10 p.m.

CVE-2023-47715 IBM Storage Protect Plus Server improper access control

2024-03-2114:10:59
CWE-269
ibm
github.com
1
cve-2023-47715
ibm storage protect plus server
access control

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

6.3

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. IBM X-Force ID: 271538.

CNA Affected

[
  {
    "vendor": "IBM",
    "product": "Storage Protect Plus Server",
    "versions": [
      {
        "status": "affected",
        "version": "10.1.0",
        "versionType": "semver",
        "lessThanOrEqual": "10.1.16"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

6.3

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-47715