Database/Control plane, storage & DevOps
Brocade SANnav Management Portal web interface, before v2.3.0 and v2.2.2a: Remote unauthenticated users can bypass web
Impact
Remote unauthenticated users can bypass web authentication and authorization on the SANnav portal. That is the front door to the whole FC management estate - fabric inventory, zoning pushes, switch credentials, firmware distribution. Chained with the zone-management SQL injection above it turns a fully unauthenticated network position into control of tenant isolation across every managed fabric.
Who can reach it
Any host with network reachability to the SANnav web interface. No credentials at all.
What to do
Upgrade SANnav to 2.3.0 or 2.2.2a. Management-plane upgrade only - no fabric or array disruption. Because the pre-fix window allowed unauthenticated access, also rotate stored switch credentials and diff the live zonesets against your intended configuration rather than assuming the upgrade closes the incident.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.