CVE-2021-29873

IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:spectrum_virtualize:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spectrum_virtualize_for_public_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storwize_v3500_software:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storwize_v3700_software:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storwize_v5000_software:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storwize_v5100_software:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storwize_v7000_software:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:san_volume_controller_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ibm:flashsystem_9100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flashsystem_9100:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ibm:flashsystem_9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flashsystem_9000:-:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-668 NVD-CWE-noinfo

26 Oct 2021, 02:03

Type Values Removed Values Added
References (CONFIRM) https://www.ibm.com/support/pages/node/6507091 - (CONFIRM) https://www.ibm.com/support/pages/node/6507091 - Patch, Vendor Advisory
References (CONFIRM) https://www.ibm.com/support/pages/node/6497111 - (CONFIRM) https://www.ibm.com/support/pages/node/6497111 - Patch, Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/206229 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/206229 - VDB Entry, Vendor Advisory
CWE CWE-668
CVSS v2 : unknown
v3 : unknown
v2 : 5.5
v3 : 8.1
CPE cpe:2.3:o:ibm:flashsystem_9100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flashsystem_9100:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spectrum_virtualize:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storwize_v3700_software:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storwize_v5100_software:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flashsystem_9000:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storwize_v5000_software:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:flashsystem_9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storwize_v3500_software:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:san_volume_controller_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spectrum_virtualize_for_public_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storwize_v7000_software:*:*:*:*:*:*:*:*

21 Oct 2021, 17:28

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-21 17:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-29873

Mitre link : CVE-2021-29873

CVE.ORG link : CVE-2021-29873


JSON object : View

Products Affected

ibm

  • storwize_v5100_software
  • flashsystem_9000_firmware
  • storwize_v5000_software
  • flashsystem_9100
  • storwize_v7000_software
  • spectrum_virtualize_for_public_cloud
  • flashsystem_9000
  • flashsystem_9100_firmware
  • storwize_v3700_software
  • storwize_v3500_software
  • san_volume_controller_firmware
  • spectrum_virtualize