Medium Severity

Security Bulletin: Vulnerability in remote support authentication affects IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products

Share this post:

A vulnerability in the challenge / response authentication mechanism used by IBM remote support may allow unauthorized access as credentials can be reused on the product’s management GUI.

CVE(s): CVE-2021-38969

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
IBM Spectrum Virtualize 8.4
IBM Spectrum Virtualize 8.3
IBM Spectrum Virtualize 8.2

Earlier code levels (e.g. 7.8.1) and later code levels (e.g. 8.5.0) are not affected.

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6584337
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/212609

More stories

Security Bulletin: Multiple Vulnerabilities found in Apache Tika used by Content Collector for Email, Content Collector for File Systems, Content Collector for Microsoft SharePoint and Content Collector for IBM Connections

June 24, 2022 | Medium Severity

Multiple Vulnerabilities found in Apache Tika used by Content Collector for Email, Content Collector for File Systems, Content Collector for Microsoft SharePoint and Content Collector for IBM Connections ...read more


Security Bulletin: Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime affect Rational Business Developer

June 24, 2022 | Medium Severity

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Version 7 and 8 and IBM® Runtime Environment Java™ Version 7 and 8 used by Rational Business Developer. Rational Business Developer has provided fixes for the applicable CVEs. These issues were disclosed as part of the IBM Java SDK and Runtime Environment updates in the January 2022 Critical Patch Update, minus CVE-2022-21299. ...read more


Security Bulletin: Vulnerability in IBM Java SDK and IBM Java Runtime affects Rational Business Developer

June 24, 2022 | Medium Severity

There is a vulnerability in IBM® SDK Java™ Technology Edition, Version 7 and 8 and IBM® Runtime Environment Java™ Version 7 and 8 used by Rational Business Developer. Rational Business Developer has provided a fix for the applicable CVE. This issue was disclosed as part of the IBM Java SDK and Runtime Environment updates deferred from Oracle Oct 2021 CPU (CVE-2021-35550). ...read more