CVE-2020-4378IBM Spectrum Scale vulnerability

3 documents3 sources
Severity
4.9MEDIUMNVD
EPSS
0.1%
top 66.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 27
Latest updateMay 24

Description

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions using a specially crated HTTP POST command. IBM X-Force ID: 179157.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

NVDibm/spectrum_scale5.0.0.05.0.4.4
CVEListV5ibm/spectrum_scale5.0.0, 5.0.4.4+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x8xv-v8v3-jc5h: IBM Spectrum Scale 52022-05-24
CVEList
CVE-2020-4378: IBM Spectrum Scale 52020-05-27
CVE-2020-4378 — IBM Spectrum Scale vulnerability | cvebase