BSA-2022-1837

Brocade Fabric OS

2 more products

21292

03 May 2022

03 May 2022

Closed

Medium

6.5 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

N/A

CVE-2018-14335

Summary

Security Advisory ID : BSA-2022-1837

Component : H2

Revision : 1.0


An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.

Affected Products.

Brocade SANnav - Fixed in Brocade SANnav 2.2.0

Product Confirmed Not Vulnerable

No other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.

Revision History

Version

Change

Date

1.0

Initial Publication

May 3, 2022