Description
IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote authenticated user to obtain sensitive information, caused by improper filtering of URLs. By submitting a specially crafted HTTP GET request, an attacker could exploit this vulnerability to view application source code, system configuration information, or other sensitive data related to the Management Interface. IBM X-Force ID: 272651.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-53777 | IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote authenticated user to obtain sensitive information, caused by improper filtering of URLs. By submitting a specially crafted HTTP GET request, an attacker could exploit this vulnerability to view application source code, system configuration information, or other sensitive data related to the Management Interface. IBM X-Force ID: 272651. |
References
History
No history.
Subscriptions
Ibm
Subscribe
Virtualization Engine Ts7760 3957-vec
Subscribe
Virtualization Engine Ts7760 3957-vec Firmware
Subscribe
Virtualization Engine Ts7770 3948-ved
Subscribe
Virtualization Engine Ts7770 3948-ved Firmware
Subscribe
Virtualization Engine Ts7770 3957-ved
Subscribe
Virtualization Engine Ts7770 3957-ved Firmware
Subscribe
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-02T22:09:48.206Z
Reserved: 2023-12-01T01:47:32.862Z
Link: CVE-2023-49877
No data.
Status : Modified
Published: 2023-12-13T21:15:08.040
Modified: 2024-11-21T08:33:58.493
Link: CVE-2023-49877
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD