CVE-2014-3077: IBM Storwize Unified v7000
Low severity, CVSS 2.1. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.
Affected products
- IBM Storwize Unified v7000
- IBM Storwize v7000 Unified Software: version 1.3.0.0 only; version 1.3.2.0 only; version 1.3.2.3 only; version 1.4.0.0 only; version 1.4.0.4 only; version 1.4.1.0 only; …
Published 2014-09-15. Last modified 2026-06-17.