Vulnerability Bulletins

IBM Security Bulletin: IBM FlashSystem 840 and IBM FlashSystem V840, -AE1 models nodes are affected by vulnerabilities in Apache’s Struts library (CVE-2014-7809)

   
Affected software IBM
 
Apache Struts could potentially allow a remote attacker to bypass security restrictions, caused by predictable tokens. CVE(s): CVE-2014-7809 Affected product(s) and affected version(s): IBM FlashSystem 840: Machine Type 9840, model -AE1 (all supported releases) Machine Type 9843, model -AE1 (all supported releases) IBM FlashSystem V840: Machine Type 9846, model -AE1 (all supported releases) Machine Type 9848, model -AE1 (all supported releases) The Service Assist GUI is the only component

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_flashsystem_840_and_ibm_flashsystem_v840_ae1_models_nodes_are_affected_by_vulnerabilities_in_apache_s_struts_library_cve_2014_7809?lang=en_us