Medium severity4.3NVD Advisory· Published Dec 13, 2023· Updated Jun 17, 2026
CVE-2023-49877
CVE-2023-49877
Description
IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote authenticated user to obtain sensitive information, caused by improper filtering of URLs. By submitting a specially crafted HTTP GET request, an attacker could exploit this vulnerability to view application source code, system configuration information, or other sensitive data related to the Management Interface. IBM X-Force ID: 272651.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:o:ibm:virtualization_engine_ts7760_3957-vec_firmware:*:*:*:*:*:*:*:*Range: <=8.52.103.23
- cpe:2.3:o:ibm:virtualization_engine_ts7770_3948-ved_firmware:*:*:*:*:*:*:*:*Range: <=8.53.1.21
- cpe:2.3:o:ibm:virtualization_engine_ts7770_3957-ved_firmware:*:*:*:*:*:*:*:*Range: <=8.52.103.23
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 8.52.103.23, 8.53.1.21
Patches
Vulnerability mechanics
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/272651nvdVDB EntryVendor Advisory
- www.ibm.com/support/pages/node/7092383nvdVendor Advisory
News mentions
0No linked articles in our index yet.