Lucene search

K

Spectrum Scale Security Vulnerabilities

cve
cve

CVE-2021-29708

IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to elevate their privileges. IBM X-Force ID: 200883.

6.7CVSS

6.1AI Score

0.0004EPSS

2021-05-25 05:15 PM
29
4
cve
cve

CVE-2021-29740

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary code in the context of process memory, potentially escalating their system privileges and taking control over the entir...

7.8CVSS

7.7AI Score

0.0004EPSS

2021-06-01 02:15 PM
22
6
cve
cve

CVE-2021-38882

IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit logging records before expiration time. IBM X-Force ID: 209164.

4.4CVSS

4.4AI Score

0.0004EPSS

2021-11-16 05:15 PM
21
cve
cve

CVE-2022-22368

IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012.

7.5CVSS

7.2AI Score

0.001EPSS

2022-05-03 07:15 PM
55
2
cve
cve

CVE-2022-22411

IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016.

6.5CVSS

6.2AI Score

0.001EPSS

2022-08-10 05:15 PM
42
8
cve
cve

CVE-2022-40607

IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem. IBM X-Force ID: 235740.

6.8CVSS

6.3AI Score

0.001EPSS

2022-12-19 08:15 PM
37
cve
cve

CVE-2022-43843

IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 239080.

7.5CVSS

7.2AI Score

0.001EPSS

2023-12-14 01:15 AM
12
cve
cve

CVE-2022-43867

IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.

7.8CVSS

7.5AI Score

0.0004EPSS

2022-12-06 07:15 PM
31
cve
cve

CVE-2022-43869

IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack. IBM X-Force ID: 239539.

6.5CVSS

6.2AI Score

0.001EPSS

2023-02-12 04:15 AM
40
cve
cve

CVE-2023-30434

IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3.0 through 6.1.6.0) could allow a local user to cause a kernel panic. IBM X-Force ID: 252187.

6.2CVSS

5.1AI Score

0.0004EPSS

2023-05-05 03:15 PM
15
Total number of security vulnerabilities60