SB2013042101 - Multiple vulnerabilities in IBM SAN Volume Controller and Storwize Family
Published: April 21, 2013 Updated: October 18, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2013-4310)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation.
2) Configuration (CVE-ID: CVE-2013-4316)
The issue may allow a remote attacker to bypass implemented security restrictions.
The issue exists due to Apache Struts enables Dynamic Method Invocation by default. A remote attacker can trigger the vulnerability to bypass implemented security restrictions.
Remediation
Install update from vendor's website.