Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in Apache Struts affects IBM System Storage Storwize V7000 Unified (CVE-2014-0094)

   
Affected software IBM
 
There is a ParametersInterceptor security bypass vulnerability in Apache Struts that is used by IBM System Storage Storwize V7000 Unified. CVE(s): CVE-2014-0094 Affected product(s) and affected version(s): IBM System Storage Storwize V7000 Unified All products are affected when running code releases 1.3 and 1.4 except for version 1.4.3.4 and above. Code release 1.5 is not affected. Refer to the following reference URLs for remediation and additional vulnerability details: Source

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_apache_struts_affects_ibm_system_storage_storwize_v7000_unified_cve_2014_0094?lang=en_us