Lucene search

K
ibmIBME2FDBB0FE9C3A0EB6D2A6BA434554C66F52E12922DCCD41169095892FC93D4B7
HistoryAug 04, 2022 - 2:24 p.m.

Security Bulletin: A vulnerability has been identified in IBM Spectrum Scale Data Access Services (DAS) where service account token configured with risky permission (CVE-2022-22411)

2022-08-0414:24:35
www.ibm.com
21
ibm spectrum scale
data access services
das
vulnerability
service account
cluster resources
permission
cve-2022-22411

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

19.6%

Summary

A security vulnerability has been identified in IBM Spectrum Scale Data Access Services (DAS) where service account token configured with risky permission. A fix for this vulnerability is available.

Vulnerability Details

CVEID:CVE-2022-22411
**DESCRIPTION:**IBM Spectrum Scale could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/223016 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Scale DAS 5.1.3.1

Remediation/Fixes

For IBM Spectrum Scale Data Access Services (DAS) V5.1.3.1, install available V5.1.4 by following the below IBM Documentation link:

<https://www.ibm.com/docs/en/scalecontainernative?topic=514-spectrum-scale-data-access-services&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmspectrum_scaleMatch5.1.3
VendorProductVersionCPE
ibmspectrum_scale5.1.3cpe:2.3:a:ibm:spectrum_scale:5.1.3:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

19.6%

Related for E2FDBB0FE9C3A0EB6D2A6BA434554C66F52E12922DCCD41169095892FC93D4B7