3.5
CVSSv2

CVE-2014-0875

Published: 07/07/2014 Updated: 07/01/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

Active Cloud Engine (ACE) in IBM Storwize V7000 Unified 1.3.0.0 up to and including 1.4.3.x allows remote malicious users to bypass intended ACL restrictions in opportunistic circumstances by leveraging incorrect ACL synchronization over an unreliable NFS connection that requires retransmissions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm storwize_unified_v7000_software 1.3.0.0

ibm storwize_unified_v7000_software 1.4.0.5

ibm storwize_unified_v7000_software 1.4.1.0

ibm storwize_unified_v7000_software 1.4.0.1

ibm storwize_unified_v7000_software 1.4.0.2

ibm storwize_unified_v7000_software 1.4.3.0

ibm storwize_unified_v7000_software 1.4.3.1

ibm storwize_unified_v7000_software 1.3.1.0

ibm storwize_unified_v7000_software 1.4.0.0

ibm storwize_unified_v7000_software 1.4.1.1

ibm storwize_unified_v7000_software 1.4.2.0

ibm storwize_unified_v7000_software 1.4.2.1

ibm storwize_unified_v7000_software 1.4.0.3

ibm storwize_unified_v7000_software 1.4.0.4

ibm storwize_unified_v7000_software 1.4.3.2

ibm storwize_unified_v7000 -