cbcvebase.

Ibm Spectrum Scale vulnerabilities

59 known vulnerabilities affecting ibm/spectrum_scale.

Total CVEs
59
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH23MEDIUM30LOW5

Vulnerabilities

Page 1 of 3
CVE-2020-4241P2HIGHCVSS 8.8≥ 10.1.0, ≤ 10.1.52020-03-31
CVE-2020-4241 [HIGH] CWE-78 CVE-2020-4241: IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenti IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175418.
nvd
CVE-2020-4242P2HIGHCVSS 8.8≥ 10.1.0, ≤ 10.1.52020-03-31
CVE-2020-4242 [HIGH] CWE-78 CVE-2020-4242: IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenti IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175419.
nvd
CVE-2019-4715P2HIGHCVSS 8.8≥ 4.2.0.0, ≤ 4.2.3.18≥ 5.0.0.0, ≤ 5.0.4.0+2 more2019-12-11
CVE-2019-4715 [HIGH] CWE-78 CVE-2019-4715: IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary comm IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172093.
nvd
CVE-2020-4926P3CRITICALCVSS 9.1fixed in 5.1.3.0v5.12022-05-24
CVE-2020-4926 [CRITICAL] CWE-862 CVE-2020-4926: A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could al A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600.
nvd
CVE-2020-4927P3HIGHCVSS 8.2≥ 5.0.5.0, < 5.1.7.0≥ 5.0.5.0, < 5.1.6.12023-03-15
CVE-2020-4927 [HIGH] CWE-200 CVE-2020-4927: A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorize A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695.
nvd
CVE-2021-29740P3HIGHCVSS 7.8≥ 5.0.0.0, < 5.0.5.7≥ 5.1.0, < 5.1.1.0+4 more2021-06-01
CVE-2021-29740 [HIGH] CWE-134 CVE-2021-29740: IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary code in the context of process memory, potentially escalating their system privileges and taking control over the entire system with root access. IBM X-Force ID: 201474.
nvd
CVE-2016-6115P3HIGHCVSS 7.2v4.1.0.0v4.1.1.0+16 more2017-02-01
CVE-2016-6115 [HIGH] CWE-119 CVE-2016-6115: IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash.
nvd
CVE-2022-43867P3HIGHCVSS 7.8≥ 5.1.0.1, < 5.1.4.12022-12-06
CVE-2022-43867 [HIGH] CWE-78 CVE-2022-43867: IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary comman IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.
nvd
CVE-2020-4850P3HIGHCVSS 7.5v1.1.1.0v1.1.8.42021-05-20
CVE-2020-4850 [HIGH] CWE-116 CVE-2020-4850: IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker t IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the leftover files after configuration. IBM X-Force ID: 190298.
nvd
CVE-2021-29667P3HIGHCVSS 7.8≥ 5.0.0, ≤ 5.0.5.6≥ 5.1.0, ≤ 5.1.0.2+4 more2021-04-27
CVE-2021-29667 [HIGH] CWE-1236 CVE-2021-29667: IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 199403.
nvd
CVE-2020-4273P3HIGHCVSS 7.8≥ 4.2.0.0, ≤ 4.2.3.20≥ 5.0.0.0, ≤ 5.0.4.2+2 more2020-04-03
CVE-2020-4273 [HIGH] CVE-2020-4273: IBM Spectrum Scale 4.2 and 5.0 could allow a local unprivileged attacker with intimate knowledge of IBM Spectrum Scale 4.2 and 5.0 could allow a local unprivileged attacker with intimate knowledge of the enviornment to execute commands as root using specially crafted input. IBM X-Force ID: 175977.
nvd
CVE-2022-22368P3HIGHCVSS 7.5≥ 5.1.0, ≤ 5.1.3.0v5.1.0+1 more2022-05-03
CVE-2022-22368 [HIGH] CWE-326 CVE-2022-22368: IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that cou IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012.
nvd
CVE-2022-43843P3HIGHCVSS 7.5v5.1.5.0v5.1.5.1+1 more2023-12-14
CVE-2022-43843 [HIGH] CWE-327 CVE-2022-43843: IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that c IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 239080.
nvd
CVE-2020-4379P3HIGHCVSS 7.5≥ 5.0.0.0, ≤ 5.0.4.4v5.0.0+1 more2020-05-27
CVE-2020-4379 [HIGH] CWE-327 CVE-2020-4379: IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that c IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179158.
nvd
CVE-2020-4349P3HIGHCVSS 7.5≥ 5.0.0.0, ≤ 5.0.4.4v5.0.0+1 more2020-05-27
CVE-2020-4349 [HIGH] CWE-327 CVE-2020-4349: IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that c IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178423.
nvd
CVE-2020-4350P3HIGHCVSS 7.5≥ 5.0.0.0, ≤ 5.0.4.4v5.0.0+1 more2020-05-27
CVE-2020-4350 [HIGH] CWE-327 CVE-2020-4350: IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that c IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178424.
nvd
CVE-2019-4558P3HIGHCVSS 7.8≥ 4.2.0.0, ≤ 4.2.3.17≥ 5.0.0.0, ≤ 5.0.3.2+4 more2019-10-09
CVE-2019-4558 [HIGH] CWE-74 CVE-2019-4558: A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5 A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4.2.3.17 that could allow a local attacker to obtain root privilege by injecting parameters into setuid files.
nvd
CVE-2020-4217P3HIGHCVSS 7.5≥ 4.2.0.0, ≤ 4.2.3.19≥ 5.0.0.0, ≤ 5.0.4.2+2 more2020-03-09
CVE-2020-4217 [HIGH] CWE-754 CVE-2020-4217: The IBM Spectrum Scale 4.2 and 5.0 file system component is affected by a denial of service security The IBM Spectrum Scale 4.2 and 5.0 file system component is affected by a denial of service security vulnerability. An attacker can force the Spectrum Scale mmfsd/mmsdrserv daemons to unexpectedly exit, impacting the functionality of the Spectrum Scale cluster and the availability of file systems managed by Spectrum Scale. IBM X-Force ID: 175067.
nvd
CVE-2018-1431P3HIGHCVSS 7.8≥ 4.1.1.0, ≤ 4.1.1.19≥ 4.2.0.0, ≤ 4.2.0.4+10 more2018-06-13
CVE-2018-1431 [HIGH] CVE-2018-1431: A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID: 139240.
nvd
CVE-2020-4348P3MEDIUMCVSS 6.5≥ 4.2.0.0, ≤ 4.2.3.21≥ 5.0.0.0, ≤ 5.0.4.4+4 more2020-05-27
CVE-2020-4348 [MEDIUM] CWE-862 CVE-2020-4348: IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform unauthorized actions due to missing function level access control. IBM X-Force ID: 178414
nvd
Ibm Spectrum Scale vulnerabilities | cvebase