CVE-2021-29667

CWE-12363 documents3 sources
Severity
7.8HIGH
EPSS
0.3%
top 45.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 27
Latest updateMay 24

Description

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 199403.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDibm/spectrum_scale5.0.05.0.5.6+1
CVEListV5ibm/spectrum_scale4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9323-phpc-vqqm: IBM Spectrum Scale 52022-05-24
CVEList
CVE-2021-29667: IBM Spectrum Scale 52021-04-27
CVE-2021-29667 (HIGH CVSS 7.8) | IBM Spectrum Scale 5.0.0 through 5. | cvebase.io