Lucene search

K
cve[email protected]CVE-2022-40607
HistoryDec 19, 2022 - 8:15 p.m.

CVE-2022-40607

2022-12-1920:15:11
CWE-22
web.nvd.nist.gov
37
ibm
spectrum scale
5.1
unauthorized access
file system
nvd
cve-2022-40607
ibm x-force id
235740

6.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.7%

IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem. IBM X-Force ID: 235740.

Affected configurations

Vulners
NVD
Node
ibmspectrum_scaleMatch5.1
VendorProductVersionCPE
ibmspectrum_scale5.1cpe:2.3:a:ibm:spectrum_scale:5.1:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Spectrum Scale",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "5.1"
      }
    ]
  }
]

6.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.7%

Related for CVE-2022-40607