Show filters
458 Total Results
Displaying 51-60 of 458
Sort by:
Attacker Value
Unknown

CVE-2024-25954

Disclosure Date: March 28, 2024 (last updated January 12, 2025)
Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
Attacker Value
Unknown

CVE-2024-25953

Disclosure Date: March 28, 2024 (last updated January 12, 2025)
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.
Attacker Value
Unknown

CVE-2024-25952

Disclosure Date: March 28, 2024 (last updated January 12, 2025)
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.
Attacker Value
Unknown

CVE-2024-25961

Disclosure Date: March 28, 2024 (last updated January 12, 2025)
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.
Attacker Value
Unknown

CVE-2024-25959

Disclosure Date: March 28, 2024 (last updated January 12, 2025)
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.
Attacker Value
Unknown

CVE-2024-25964

Disclosure Date: March 25, 2024 (last updated January 12, 2025)
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
Attacker Value
Unknown

CVE-2024-24901

Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specific time period.
Attacker Value
Unknown

CVE-2024-22463

Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to compromise of confidentiality and integrity of sensitive information
Attacker Value
Unknown

CVE-2024-0560

Disclosure Date: February 28, 2024 (last updated January 22, 2025)
A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy discovers the Token Introspection endpoint from the token_introspection_endpoint field, but the field was removed on RH-SSO 7.5. As a result, the policy doesn't inspect tokens, it determines that all tokens are valid.
Attacker Value
Unknown

CVE-2022-41738

Disclosure Date: February 17, 2024 (last updated January 06, 2025)
IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.