Vulnerability Name:

CVE-2004-2759 (CCN-17901)

Assigned:2004-08-10
Published:2004-08-10
Updated:2017-08-08
Summary:Shared Sun StorEdge QFS and SAM-QFS file systems, as used in Utilization Suite 4.0 through 4.1 and Performance Suite 4.0 through 4.1, might allow local users to read portions of deleted files by accessing data within sparse files.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2004-2759

Source: SUNALERT
Type: UNKNOWN
101527

Source: CCN
Type: Sun Alert ID: 57595
Sparse Files Written to Shared Sun StorEdge QFS or Sun StorEdge SAM-QFS File Systems May Contain Deleted File Contents

Source: SUNALERT
Type: UNKNOWN
200184

Source: CCN
Type: OSVDB ID: 43117
Sun StorEdge Multiple Products QFS Filesystem Deleted File Content Local Disclosure

Source: BID
Type: UNKNOWN
11559

Source: CCN
Type: BID-11559
Sun StorEdge Sparse File Information Disclosure Vulnerability

Source: XF
Type: UNKNOWN
storedge-deleted-obtain-info(17901)

Source: XF
Type: UNKNOWN
storedge-deleted-obtain-info(17901)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:storedge_qfs:*:*:*:*:*:*:*:*
  • OR cpe:/a:sun:storedge_sam-qfs:*:*:*:*:*:*:*:*
  • OR cpe:/a:sun:storeedge_performance_suite:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:sun:storeedge_performance_suite:4.1:*:*:*:*:*:*:*
  • OR cpe:/a:sun:storeedge_utilization_suite:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:sun:storeedge_utilization_suite:4.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun storedge qfs *
    sun storedge sam-qfs *
    sun storeedge performance suite 4.0
    sun storeedge performance suite 4.1
    sun storeedge utilization suite 4.0
    sun storeedge utilization suite 4.1