CVE-2021-29873
Published: Oct 21, 2021
Modified: Sep 16, 2024
CVSS v3.0
8.8
Description
IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.
| Vendor | Product | Versions |
|---|---|---|
IBM | FlashSystem 900 | affected 1.6.1.4affected 1.5.2.10 |
IBM | FlashSystem V9000 | affected 7.8affected 8.4 |
IBM | Storwize V3500 | affected 7.8affected 8.4 |
IBM | Storwize V5000 | affected 7.8affected 8.4 |
IBM | Storwize V5100 | affected 8.4affected 7.8 |
IBM | FlashSystem 9100 Family | affected 8.4affected 7.8 |
IBM | Storwize V3700 | affected 7.8affected 8.4 |
IBM | SAN Volume Controller | affected 7.8affected 8.4 |
IBM | Storwize V7000 | affected 8.4affected 7.8 |
IBM | Spectrum Virtualize Software | affected 7.8affected 8.4 |
IBM | Spectrum Virtualize for Public Cloud | affected 7.8affected 8.4 |
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/A:H/AV:N/I:H/PR:L/C:H/S:U/UI:N/AC:L/E:U/RC:C/RL:O
Availability
Attack Vector
Integrity
Privileges Required
Confidentiality
Scope
User Interaction
Attack Complexity
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now