IBM / Spectrum Scale
58 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-41738 | IBM Spectrum Scale security bypass | HIGH | 7.5 | Feb 17, 2024 |
| CVE-2022-43843 | IBM Spectrum Scale information disclosure | HIGH | 7.5 | Dec 14, 2023 |
| CVE-2023-30434 | IBM Storage Scale denial of service | MEDIUM | 6.2 | May 5, 2023 |
| CVE-2020-4927 | IBM Spectrum Scale information disclosure | HIGH | 8.2 | Mar 15, 2023 |
| CVE-2022-43869 | IBM Spectrum Scale denial of service | MEDIUM | 6.5 | Feb 8, 2023 |
| CVE-2022-40607 | IBM Spectrum Scale directory traversal | MEDIUM | 6.8 | Dec 19, 2022 |
| CVE-2022-43867 | IBM Spectrum Scale command execution | HIGH | 7.8 | Dec 6, 2022 |
| CVE-2020-4926 | A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitr… | CRITICAL | 9.1 | May 24, 2022 |
| CVE-2022-22368 | IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informatio… | HIGH | 7.5 | May 3, 2022 |
| CVE-2020-4925 | A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requests and preventing the daemon to servi… | MEDIUM | 5.5 | Mar 1, 2022 |
| CVE-2021-38882 | IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit logging records before expiration time. IBM X-Force ID: 209… | MEDIUM | 4.4 | Nov 16, 2021 |
| CVE-2021-29740 | IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker cou… | HIGH | 7.8 | Jun 1, 2021 |
| CVE-2021-29708 | IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to elevate the… | MEDIUM | 6.7 | May 25, 2021 |
| CVE-2020-4850 | IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the leftover file… | HIGH | 7.5 | May 20, 2021 |
| CVE-2021-29667 | IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary comman… | HIGH | 7.8 | Apr 27, 2021 |
| CVE-2021-29666 | IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja… | MEDIUM | 5.4 | Apr 27, 2021 |
| CVE-2020-4981 | IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 192541. | MEDIUM | 6.0 | Apr 27, 2021 |
| CVE-2021-29671 | IBM Spectrum Scale 5.1.0.1 could allow a local attacker to bypass the filesystem audit logging mechanism when file audit logging is enabled. IBM X-Force ID: 19… | LOW | 3.3 | Apr 9, 2021 |
| CVE-2020-4891 | IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force R… | MEDIUM | 5.5 | Mar 16, 2021 |
| CVE-2020-4890 | IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user with a valid role to the REST API to cause a denial of service due… | MEDIUM | 4.4 | Mar 16, 2021 |
| CVE-2020-4851 | IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and development effo… | MEDIUM | 5.5 | Mar 16, 2021 |
| CVE-2020-4889 | IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force… | LOW | 3.3 | Jan 26, 2021 |
| CVE-2020-4756 | IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local att… | MEDIUM | 5.5 | Oct 20, 2020 |
| CVE-2020-4755 | IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U… | MEDIUM | 5.4 | Oct 20, 2020 |
| CVE-2020-4749 | IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie… | MEDIUM | 4.3 | Oct 20, 2020 |
Showing 1 to 25 of 58 CVEs