Ibm Spectrum Scale vulnerabilities
59 known vulnerabilities affecting ibm/spectrum_scale.
Total CVEs
59
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH23MEDIUM30LOW5
Vulnerabilities
Page 3 of 3
CVE-2020-4891P4MEDIUMCVSS 5.5≥ 5.0.0.0, ≤ 5.0.5.5≥ 5.1.0.0, ≤ 5.1.0.2+4 more2021-03-16
CVE-2020-4891 [MEDIUM] CWE-307 CVE-2020-4891: IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockou
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials. IBM X-Force ID: 190974.
nvd
CVE-2020-4411P4HIGHCVSS 7.1≥ 4.2.0.0, ≤ 4.2.3.21≥ 5.0.0.0, ≤ 5.0.4.3+4 more2020-05-19
CVE-2020-4411 [HIGH] CWE-20 CVE-2020-4411: The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is aff
The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its kernel module that could allow an attacker to cause a denial of service condition on the affected system. To exploit this vulnerability, a local attacker could invoke a subset of ioctls on the Spectrum Scal
nvd
CVE-2020-4981P4MEDIUMCVSS 6.0≥ 5.0.4.1, ≤ 5.1.0.3v5.0.4.1+1 more2021-04-27
CVE-2020-4981 [MEDIUM] CWE-20 CVE-2020-4981: IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files du
IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 192541.
nvd
CVE-2020-4925P4MEDIUMCVSS 5.5v5.0.0v5.1.0+2 more2022-03-01
CVE-2020-4925 [MEDIUM] CVE-2020-4925: A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mm
A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requests and preventing the daemon to service other requests. IBM X-Force ID: 191599.
nvd
CVE-2018-1783P4MEDIUMCVSS 5.5≥ 4.1.0.0, ≤ 4.1.1.20≥ 4.2.0.0, ≤ 4.2.3.10+1 more2018-10-05
CVE-2018-1783 [MEDIUM] CVE-2018-1783: IBM GPFS (IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2) command line u
IBM GPFS (IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2) command line utility allows an unprivileged, authenticated user with access to a GPFS node to forcefully terminate GPFS and deny access to data available through GPFS. IBM X-Force ID: 148806.
nvd
CVE-2023-30434P4MEDIUMCVSS 5.5≥ 5.1.0.0, ≤ 5.1.2.9≥ 5.1.3.0, ≤ 5.1.6.12023-05-05
CVE-2023-30434 [MEDIUM] CWE-20 CVE-2023-30434: IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elast
IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3.0 through 6.1.6.0) could allow a local user to cause a kernel panic. IBM X-Force ID: 252187.
nvd
CVE-2020-4756P4MEDIUMCVSS 5.5≤ 4.2.3.23≤ 5.0.5.2+4 more2020-10-20
CVE-2020-4756 [MEDIUM] CWE-404 CVE-2020-4756: IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic S
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service. IBM X-Force ID: 188599.
nvd
CVE-2020-4492P4MEDIUMCVSS 5.5≥ 4.2.0.0, ≤ 4.2.3.21≥ 5.0.0.0, ≤ 5.0.4.3+4 more2020-08-31
CVE-2020-4492 [MEDIUM] CWE-88 CVE-2020-4492: IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local atta
IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device with invalid arguments. IBM X-Force ID: 181992.
nvd
CVE-2020-4491P4MEDIUMCVSS 5.5≤ 4.2.3.22≤ 5.0.5+4 more2020-10-20
CVE-2020-4491 [MEDIUM] CVE-2020-4491: IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attack
IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial of service by sending a large number of RPC requests to the mmfsd daemon which would cause the service to crash. IBM X-Force ID: 181991.
nvd
CVE-2020-4749P4MEDIUMCVSS 4.3≤ 5.0.5.2v5.0.0+1 more2020-10-20
CVE-2020-4749 [MEDIUM] CWE-565 CVE-2020-4749: IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens o
IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by
nvd
CVE-2020-4357P4MEDIUMCVSS 4.3≥ 5.0.0.0, ≤ 5.0.4.4v5.0.0+1 more2020-05-27
CVE-2020-4357 [MEDIUM] CWE-209 CVE-2020-4357: IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive informa
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 178761.
nvd
CVE-2021-38882P4MEDIUMCVSS 4.4≥ 5.1.0, ≤ 5.1.1.1v5.1.0+1 more2021-11-16
CVE-2021-38882 [MEDIUM] CVE-2021-38882: IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit
IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit logging records before expiration time. IBM X-Force ID: 209164.
nvd
CVE-2020-4890P4MEDIUMCVSS 4.4≥ 5.0.0.0, ≤ 5.0.5.5≥ 5.1.0.0, ≤ 5.1.0.2+4 more2021-03-16
CVE-2020-4890 [MEDIUM] CVE-2020-4890: IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user with a v
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user with a valid role to the REST API to cause a denial of service due to weak or absense of rate limiting. IBM X-Force ID: 190973.
nvd
CVE-2015-7403P4MEDIUMCVSS 4.0v4.1.1.0v4.1.1.1+1 more2016-01-02
CVE-2015-7403 [MEDIUM] CVE-2015-7403: IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0
IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors.
nvd
CVE-2017-1654P4LOWCVSS 3.3≥ 4.1.1.0, ≤ 4.1.1.18≥ 4.2.0.0, ≤ 4.2.0.4+9 more2018-03-02
CVE-2017-1654 [LOW] CWE-200 CVE-2017-1654: IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to informati
IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.
nvd
CVE-2020-4889P4LOWCVSS 3.3≥ 5.0.0, ≤ 5.0.5.4v5.1.0+3 more2021-01-26
CVE-2020-4889 [LOW] CVE-2020-4889: IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files whic
IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190971.
nvd
CVE-2021-29671P4LOWCVSS 3.3≥ 5.1.0.1, < 5.1.0.2v5.1.0.12021-04-09
CVE-2021-29671 [LOW] CVE-2021-29671: IBM Spectrum Scale 5.1.0.1 could allow a local attacker to bypass the filesystem audit logging mecha
IBM Spectrum Scale 5.1.0.1 could allow a local attacker to bypass the filesystem audit logging mechanism when file audit logging is enabled. IBM X-Force ID: 199478.
nvd
CVE-2018-1993P4LOWCVSS 3.3≥ 4.1.1.0, ≤ 4.1.1.21≥ 4.2.0.0, ≤ 4.2.3.11+7 more2019-01-08
CVE-2018-1993 [LOW] CWE-200 CVE-2018-1993: IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read O
IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.
nvd
CVE-2015-4981P4LOWCVSS 2.1v4.1.1.0v4.1.1.12015-10-26
CVE-2015-4981 [LOW] CWE-200 CVE-2015-4981: IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors.
nvd
← Previous3 / 3