CVE-2023-47715: IBM Storage Protect Plus Server improper access control
IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. IBM X-Force ID: 271538.
Other sources
IBM Storage Protect Plus Server could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47715?
CVE-2023-47715 has been categorized as a medium severity vulnerability.
How do I fix CVE-2023-47715?
To fix CVE-2023-47715, upgrade IBM Storage Protect Plus Server to version 10.1.17 or later.
Who is affected by CVE-2023-47715?
CVE-2023-47715 affects IBM Storage Protect Plus Server versions 10.1.0 through 10.1.16.
What type of vulnerability is CVE-2023-47715?
CVE-2023-47715 is a configuration manipulation vulnerability that allows unauthorized changes by authenticated users.
Can read-only authenticated users exploit CVE-2023-47715?
Yes, authenticated users with read-only permissions can exploit CVE-2023-47715 to modify HyperVisor configurations.