CERT-In Vulnerability Note
CIVN-2023-0388
Remote Code Execution Vulnerability in IBM Storage Fusion
Original Issue Date:December 26, 2023
Severity Rating: HIGH
Software Affected
- IBM Storage Fusion 2.1.0 - 2.6.1
Overview
A vulnerability has been reported in IBM Storage Fusion, which could allow a remote attacker to execute arbitrary code on the targeted system.
Description
This vulnerability exists in IBM Storage Fusion due to improper neutralization of user supplied-input by the org.quartz.jobs.ee.jms.SendQueueMessageJob.execute component. An attacker could exploit this vulnerability by sending a specially crafted request.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate remediation/fixes issued by the vendor:
https://www.ibm.com/support/pages/node/7099335
Vendor Information
IBM
https://www.ibm.com/support/pages/node/7099335
References
IBM
https://www.ibm.com/support/pages/node/7099335
CVE Name
CVE-2023-39017
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|