Lucene search

K

Spectrum Scale Security Vulnerabilities

cve
cve

CVE-2015-4974

IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.

4.2AI Score

0.0004EPSS

2015-10-26 02:59 AM
24
cve
cve

CVE-2015-4981

IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors.

3.7AI Score

0.0004EPSS

2015-10-26 02:59 AM
26
cve
cve

CVE-2015-7403

IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors.

4CVSS

4.1AI Score

0.001EPSS

2016-01-02 09:59 PM
23
cve
cve

CVE-2015-7456

IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows remote authenticated users to discover object-storage admin passwords via unspecified vectors.

6.5CVSS

6AI Score

0.001EPSS

2016-01-01 11:59 AM
15
cve
cve

CVE-2015-7488

IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover an LDAP password via unspecified vectors.

5.9CVSS

5.6AI Score

0.002EPSS

2016-01-27 05:59 AM
22
cve
cve

CVE-2016-0263

IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command.

7CVSS

6.8AI Score

0.0004EPSS

2016-06-29 01:59 AM
17
cve
cve

CVE-2016-2984

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted command-line parameters to a /usr/lpp/mmfs/bin/ setuid program.

7CVSS

6.7AI Score

0.0004EPSS

2016-11-25 03:59 AM
15
cve
cve

CVE-2016-2985

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.

7CVSS

6.7AI Score

0.0004EPSS

2016-11-25 03:59 AM
21
cve
cve

CVE-2016-6115

IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash.

7.2CVSS

7.3AI Score

0.046EPSS

2017-02-01 10:59 PM
17
cve
cve

CVE-2017-1654

IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.

4CVSS

3.4AI Score

0.001EPSS

2018-03-02 05:29 PM
27
cve
cve

CVE-2018-1431

A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. I...

7.8CVSS

8.1AI Score

0.0004EPSS

2018-06-13 02:29 PM
25
cve
cve

CVE-2018-1723

IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2 could allow an unprivileged, authenticated user with access to a GPFS node to read arbitrary files available on this node. IBM X-Force ID: 147373.

6.2CVSS

5.3AI Score

0.001EPSS

2018-10-05 01:29 PM
18
cve
cve

CVE-2018-1782

IBM GPFS (IBM Spectrum Scale 5.0.1.0 and 5.0.1.1) allows a local, unprivileged user to cause a kernel panic on a node running GPFS by accessing a file that is stored on a GPFS file system with mmap, or by executing a crafted file stored on a GPFS file system. IBM X-Force ID: 148805.

6.5CVSS

6.1AI Score

0.0004EPSS

2018-09-19 03:29 PM
18
2
cve
cve

CVE-2018-1783

IBM GPFS (IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2) command line utility allows an unprivileged, authenticated user with access to a GPFS node to forcefully terminate GPFS and deny access to data available through GPFS. IBM X-Force ID: 148806.

5.5CVSS

5.2AI Score

0.0004EPSS

2018-10-05 01:29 PM
17
cve
cve

CVE-2018-1993

IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.

4CVSS

3.7AI Score

0.001EPSS

2019-01-08 04:29 PM
19
cve
cve

CVE-2019-4259

A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES stack enabled that could allow sensitive data to be included with service snaps. IBM X-Force ID: 160011.

5.5CVSS

5.3AI Score

0.0004EPSS

2019-05-13 04:29 PM
544
cve
cve

CVE-2019-4558

A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4.2.3.17 that could allow a local attacker to obtain root privilege by injecting parameters into setuid files.

7.8CVSS

7.3AI Score

0.0004EPSS

2019-10-09 04:15 PM
19
cve
cve

CVE-2019-4665

IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171247.

5.4CVSS

5.2AI Score

0.001EPSS

2019-12-11 03:15 PM
19
cve
cve

CVE-2019-4715

IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172093.

8.8CVSS

8.6AI Score

0.002EPSS

2019-12-11 03:15 PM
17
cve
cve

CVE-2020-4217

The IBM Spectrum Scale 4.2 and 5.0 file system component is affected by a denial of service security vulnerability. An attacker can force the Spectrum Scale mmfsd/mmsdrserv daemons to unexpectedly exit, impacting the functionality of the Spectrum Scale cluster and the availability of file systems m...

7.5CVSS

7.2AI Score

0.001EPSS

2020-03-09 03:15 PM
23
cve
cve

CVE-2020-4241

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-For...

8.8CVSS

8.6AI Score

0.109EPSS

2020-03-31 03:15 PM
26
cve
cve

CVE-2020-4242

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-For...

8.8CVSS

8.6AI Score

0.109EPSS

2020-03-31 03:15 PM
24
cve
cve

CVE-2020-4273

IBM Spectrum Scale 4.2 and 5.0 could allow a local unprivileged attacker with intimate knowledge of the enviornment to execute commands as root using specially crafted input. IBM X-Force ID: 175977.

7.8CVSS

7.6AI Score

0.0004EPSS

2020-04-03 01:15 PM
60
cve
cve

CVE-2020-4348

IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform unauthorized actions due to missing function level access control. IBM X-Force ID: 178414

6.5CVSS

6.2AI Score

0.001EPSS

2020-05-27 02:15 PM
19
cve
cve

CVE-2020-4349

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178423.

7.5CVSS

7.2AI Score

0.001EPSS

2020-05-27 02:15 PM
17
cve
cve

CVE-2020-4350

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178424.

7.5CVSS

7.2AI Score

0.001EPSS

2020-05-27 02:15 PM
19
cve
cve

CVE-2020-4357

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 178761.

4.3CVSS

4.1AI Score

0.001EPSS

2020-05-27 02:15 PM
19
cve
cve

CVE-2020-4358

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178762.

5.4CVSS

5.2AI Score

0.001EPSS

2020-05-27 02:15 PM
20
cve
cve

CVE-2020-4378

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions using a specially crated HTTP POST command. IBM X-Force ID: 179157.

4.9CVSS

4.7AI Score

0.001EPSS

2020-05-27 02:15 PM
18
cve
cve

CVE-2020-4379

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179158.

7.5CVSS

7.2AI Score

0.001EPSS

2020-05-27 02:15 PM
18
cve
cve

CVE-2020-4411

The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its kernel module that could allow an attacker to cause a denial of service condition on the affected system. To exploit this vulnerability, a local atta...

7.1CVSS

6.3AI Score

0.0005EPSS

2020-05-19 02:15 PM
21
cve
cve

CVE-2020-4412

The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service security vulnerability. An attacker can force the Spectrum Scale mmfsd/mmsdrserv daemons to unexpectedly exit, impacting the functionality of the Spectrum Scale cluster a...

5.3CVSS

5.3AI Score

0.001EPSS

2020-05-19 02:15 PM
18
cve
cve

CVE-2020-4491

IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial of service by sending a large number of RPC requests to the mmfsd daemon which would cause the service to crash. IBM X-Force ID: 181991.

5.5CVSS

5.3AI Score

0.0004EPSS

2020-10-20 03:15 PM
18
cve
cve

CVE-2020-4492

IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device with invalid arguments. IBM X-Force ID: 181992.

5.5CVSS

5.1AI Score

0.0004EPSS

2020-08-31 01:15 PM
29
cve
cve

CVE-2020-4748

IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188517.

6.1CVSS

5.8AI Score

0.001EPSS

2020-10-20 03:15 PM
23
cve
cve

CVE-2020-4749

IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link...

4.3CVSS

4.8AI Score

0.001EPSS

2020-10-20 03:15 PM
21
cve
cve

CVE-2020-4755

IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188595.

5.4CVSS

5.4AI Score

0.001EPSS

2020-10-20 03:15 PM
21
cve
cve

CVE-2020-4756

IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service. IBM X-Fo...

5.5CVSS

5.1AI Score

0.0004EPSS

2020-10-20 03:15 PM
18
cve
cve

CVE-2020-4850

IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the leftover files after configuration. IBM X-Force ID: 190298.

7.5CVSS

7.2AI Score

0.002EPSS

2021-05-20 03:15 PM
13
cve
cve

CVE-2020-4851

IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190450.

5.5CVSS

5.2AI Score

0.0004EPSS

2021-03-16 02:15 PM
16
3
cve
cve

CVE-2020-4889

IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190971.

3.3CVSS

3.8AI Score

0.0004EPSS

2021-01-26 03:15 PM
14
cve
cve

CVE-2020-4890

IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user with a valid role to the REST API to cause a denial of service due to weak or absense of rate limiting. IBM X-Force ID: 190973.

4.4CVSS

4.8AI Score

0.0004EPSS

2021-03-16 02:15 PM
18
2
cve
cve

CVE-2020-4891

IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials. IBM X-Force ID: 190974.

5.5CVSS

5.2AI Score

0.0004EPSS

2021-03-16 02:15 PM
15
6
cve
cve

CVE-2020-4925

A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requests and preventing the daemon to service other requests. IBM X-Force ID: 191599.

5.5CVSS

5.4AI Score

0.0004EPSS

2022-03-01 05:15 PM
28
cve
cve

CVE-2020-4926

A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600.

9.1CVSS

8.8AI Score

0.001EPSS

2022-05-24 05:15 PM
29
10
cve
cve

CVE-2020-4927

A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695.

8.2CVSS

7.9AI Score

0.001EPSS

2023-03-15 07:15 PM
37
cve
cve

CVE-2020-4981

IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 192541.

6CVSS

5.6AI Score

0.0004EPSS

2021-04-27 05:15 PM
19
6
cve
cve

CVE-2021-29666

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session....

5.4CVSS

5.5AI Score

0.001EPSS

2021-04-27 05:15 PM
18
4
cve
cve

CVE-2021-29667

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 199403.

7.8CVSS

7.8AI Score

0.001EPSS

2021-04-27 05:15 PM
23
5
cve
cve

CVE-2021-29671

IBM Spectrum Scale 5.1.0.1 could allow a local attacker to bypass the filesystem audit logging mechanism when file audit logging is enabled. IBM X-Force ID: 199478.

3.3CVSS

3.8AI Score

0.0004EPSS

2021-04-09 05:15 PM
16
Total number of security vulnerabilities60