CVE-2018-1993Sensitive Information Exposure in IBM Spectrum Scale

Severity
3.3LOWNVD
CNA4.0
EPSS
0.1%
top 82.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 8
Latest updateMay 13

Description

IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDibm/spectrum_scale4.1.1.04.1.1.21+2
CVEListV5ibm/spectrum_scale6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c57r-54fv-vmmq: IBM Spectrum Scale (GPFS) 42022-05-13
CVEList
CVE-2018-1993: IBM Spectrum Scale (GPFS) 42019-01-08
CVE-2018-1993 — Sensitive Information Exposure in IBM | cvebase