Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2024-31892

Disclosure Date: December 14, 2024 (last updated December 18, 2024)
IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and modifying a csv file due to improper neutralization of formula elements.
Attacker Value
Unknown

CVE-2024-31891

Disclosure Date: December 14, 2024 (last updated December 18, 2024)
IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host operating system.
Attacker Value
Unknown

CVE-2023-38002

Disclosure Date: April 30, 2024 (last updated May 01, 2024)
IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or manipulate an active session to gain access to the system. IBM X-Force ID: 260208.
0
Attacker Value
Unknown

CVE-2022-41738

Disclosure Date: February 17, 2024 (last updated January 06, 2025)
IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.
Attacker Value
Unknown

CVE-2022-41737

Disclosure Date: February 17, 2024 (last updated January 06, 2025)
IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811.
Attacker Value
Unknown

CVE-2022-43831

Disclosure Date: July 31, 2023 (last updated October 08, 2023)
IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.6.1 could allow a local user to obtain escalated privileges on a host without proper security context settings configured. IBM X-Force ID: 238941.
Attacker Value
Unknown

CVE-2023-30434

Disclosure Date: May 05, 2023 (last updated October 08, 2023)
IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3.0 through 6.1.6.0) could allow a local user to cause a kernel panic. IBM X-Force ID: 252187.
Attacker Value
Unknown

CVE-2022-41736

Disclosure Date: April 29, 2023 (last updated October 08, 2023)
IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that could allow a local user to obtain root privileges. IBM X-Force ID: 237810.
Attacker Value
Unknown

CVE-2022-41739

Disclosure Date: April 26, 2023 (last updated October 08, 2023)
IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs running inside the container to overcome isolation mechanism and gain additional capabilities or access sensitive information on the host. IBM X-Force ID: 237815.
Attacker Value
Unknown

CVE-2022-43869

Disclosure Date: February 12, 2023 (last updated November 08, 2023)
IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack. IBM X-Force ID: 239539.