Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows: Fujitsu Software Infrastructure Manager Advanced Edition V2.8.0.060, Fujitsu Software Infrastructure Manager Advanced Edition for PRIMEFLEX V2.8.0.060, and Fujitsu Software Infrastructure Manager Essential Edition V2.8.0.060.
References
Link | Resource |
---|---|
https://jvn.jp/en/jp/JVN38847224/ | Third Party Advisory |
https://support.ts.fujitsu.com/IndexProdSecurity.asp?lng=en | Product |
Configurations
Configuration 1 (hide)
|
History
09 Aug 2023, 12:25
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
References | (MISC) https://jvn.jp/en/jp/JVN38847224/ - Third Party Advisory | |
References | (MISC) https://support.ts.fujitsu.com/IndexProdSecurity.asp?lng=en - Product | |
First Time |
Fujitsu software Infrastructure Manager
Fujitsu |
|
CWE | CWE-312 | |
CPE | cpe:2.3:a:fujitsu:software_infrastructure_manager:2.8.0.060:*:*:*:advanced:-:*:* cpe:2.3:a:fujitsu:software_infrastructure_manager:2.8.0.060:*:*:*:essential:*:*:* cpe:2.3:a:fujitsu:software_infrastructure_manager:2.8.0.060:*:*:*:advanced:primeflex:*:* |
04 Aug 2023, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-04 10:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-39379
Mitre link : CVE-2023-39379
CVE.ORG link : CVE-2023-39379
JSON object : View
Products Affected
fujitsu
- software_infrastructure_manager
CWE
CWE-312
Cleartext Storage of Sensitive Information