Page 2 of 62 results (0.003 seconds)

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695. • https://exchange.xforce.ibmcloud.com/vulnerabilities/191695 https://www.ibm.com/support/pages/node/6960571 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.5EPSS: 0%CPEs: 5EXPL: 0

IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack. IBM X-Force ID: 239539. • https://exchange.xforce.ibmcloud.com/vulnerabilities/239539 https://www.ibm.com/support/pages/node/6909465 https://www.ibm.com/support/pages/node/6909469 • CWE-134: Use of Externally-Controlled Format String •

CVSS: 6.8EPSS: 0%CPEs: 2EXPL: 0

IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem. IBM X-Force ID: 235740. IBM Spectrum Scale 5.1 podría permitir a los usuarios con permisos para crear pods, volúmenes persistentes y reclamaciones de volumen persistentes acceder a archivos y directorios fuera del volumen, incluso en el sistema de archivos del host. ID de IBM X-Force: 235740. • https://exchange.xforce.ibmcloud.com/vulnerabilities/235740 https://www.ibm.com/support/pages/node/6848231 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437. IBM Spectrum Scale v5.1.0.1 a v5.1.4.1 podría permitir que un atacante local ejecute comandos arbitrarios en el contenedor. ID de IBM X-Force: 239437. • https://exchange.xforce.ibmcloud.com/vulnerabilities/239437 https://www.ibm.com/support/pages/node/6844771 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 0

IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016. IBM Spectrum Scale Data Access Services (DAS) versión 5.1.3.1, podría permitir a un usuario autenticado insertar código que podría permitir al atacante manipular los recursos del clúster debido a un exceso de permisos. IBM X-Force ID: 223016 • https://exchange.xforce.ibmcloud.com/vulnerabilities/223016 https://www.ibm.com/support/pages/node/6610277 • CWE-732: Incorrect Permission Assignment for Critical Resource •