Vulnerability Bulletins

IBM Security Bulletin: Administrator password can be reset without authentication on the IBM V7000 Unified (CVE-2014-4811)

   
Affected software IBM
 
The administrator superuser password can be reset to a default value without requiring prior authentication CVE(s): CVE-2014-4811 Affected product(s) and affected version(s): IBM Storwize V7000 Unified All version 1.4 fix levels starting with 1.4.3.0 and up to but not including version 1.4.3.4 are impacted. No other code releases are vulnerable. Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_administrator_password_can_be_reset_without_authentication_on_the_ibm_v7000_unified_cve_2014_4811?lang=en_us