CVE-2022-40607

CWE-22Path Traversal3 documents3 sources
Severity
6.8MEDIUM
EPSS
0.4%
top 40.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19

Description

IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem. IBM X-Force ID: 235740.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:NExploitability: 2.3 | Impact: 4.0

Affected Packages2 packages

NVDibm/spectrum_scale5.1.4.0
CVEListV5ibm/spectrum_scale5.1

🔴Vulnerability Details

2
CVEList
IBM Spectrum Scale directory traversal2022-12-19
GHSA
GHSA-76w5-p7qg-p8gv: IBM Spectrum Scale 52022-12-19
CVE-2022-40607 (MEDIUM CVSS 6.8) | IBM Spectrum Scale 5.1 could allow | cvebase.io