Show filters
64 Total Results
Displaying 31-40 of 64
Sort by:
Attacker Value
Unknown

CVE-2020-4756

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service. IBM X-Force ID: 188599.
Attacker Value
Unknown

CVE-2020-4492

Disclosure Date: August 28, 2020 (last updated February 22, 2025)
IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device with invalid arguments. IBM X-Force ID: 181992.
Attacker Value
Unknown

CVE-2020-4348

Disclosure Date: May 26, 2020 (last updated February 21, 2025)
IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform unauthorized actions due to missing function level access control. IBM X-Force ID: 178414
Attacker Value
Unknown

CVE-2020-4378

Disclosure Date: May 26, 2020 (last updated November 27, 2024)
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions using a specially crated HTTP POST command. IBM X-Force ID: 179157.
Attacker Value
Unknown

CVE-2020-4358

Disclosure Date: May 26, 2020 (last updated February 21, 2025)
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178762.
Attacker Value
Unknown

CVE-2020-4349

Disclosure Date: May 26, 2020 (last updated February 21, 2025)
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178423.
Attacker Value
Unknown

CVE-2020-4357

Disclosure Date: May 26, 2020 (last updated February 21, 2025)
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 178761.
Attacker Value
Unknown

CVE-2020-4379

Disclosure Date: May 26, 2020 (last updated February 21, 2025)
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179158.
Attacker Value
Unknown

CVE-2020-4350

Disclosure Date: May 26, 2020 (last updated February 21, 2025)
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178424.
Attacker Value
Unknown

CVE-2020-4411

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its kernel module that could allow an attacker to cause a denial of service condition on the affected system. To exploit this vulnerability, a local attacker could invoke a subset of ioctls on the Spectrum Scale device with non-valid arguments. This could allow the attacker to crash the kernel. IBM X-Force ID: 179986.