Vulnerability Bulletins |
IBM Security Bulletin: The IBM FlashSystem V840 product model numbers AC0 and AC1 nodes are affected by vulnerabilities in Apache’s Struts library (CVE-2014-7809) |
|
| Affected software | IBM |
|
Apache Struts could potentially allow a remote attacker to bypass security restrictions, caused by predictable tokens. CVE(s): CVE-2014-7809 Affected product(s) and affected version(s): FlashSystem V840 including machine type models (all available code levels) 9846-AC0, 9848-AC0, 9846-AC1, & 9848-AC1. The Service Assist GUI is the only component in these products that uses the Apache Struts library. Refer to the following reference URLs for remediation and additional vulnerability More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_the_ibm_flashsystem_v840_product_model_numbers_ac0_and_ac1_nodes_are_affected_by_vulnerabilities_in_apache_s_struts_library_cve_2014_7809?lang=en_us |
|






