Show filters
64 Total Results
Displaying 11-20 of 64
Sort by:
Attacker Value
Unknown

CVE-2022-43867

Disclosure Date: December 06, 2022 (last updated November 08, 2023)
IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.
Attacker Value
Unknown

CVE-2022-22411

Disclosure Date: August 04, 2022 (last updated October 08, 2023)
IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016.
Attacker Value
Unknown

CVE-2020-4926

Disclosure Date: May 23, 2022 (last updated October 07, 2023)
A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600.
Attacker Value
Unknown

CVE-2022-22368

Disclosure Date: May 02, 2022 (last updated October 07, 2023)
IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012.
Attacker Value
Unknown

CVE-2020-4925

Disclosure Date: February 28, 2022 (last updated October 07, 2023)
A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requests and preventing the daemon to service other requests. IBM X-Force ID: 191599.
Attacker Value
Unknown

CVE-2021-38882

Disclosure Date: November 15, 2021 (last updated October 07, 2023)
IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit logging records before expiration time. IBM X-Force ID: 209164.
Attacker Value
Unknown

CVE-2021-29740

Disclosure Date: May 31, 2021 (last updated February 22, 2025)
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary code in the context of process memory, potentially escalating their system privileges and taking control over the entire system with root access. IBM X-Force ID: 201474.
Attacker Value
Unknown

CVE-2021-29708

Disclosure Date: May 24, 2021 (last updated November 28, 2024)
IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to elevate their privileges. IBM X-Force ID: 200883.
Attacker Value
Unknown

CVE-2020-4981

Disclosure Date: April 26, 2021 (last updated February 22, 2025)
IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 192541.
Attacker Value
Unknown

CVE-2021-29666

Disclosure Date: April 26, 2021 (last updated February 22, 2025)
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199400.