Page 3 of 62 results (0.005 seconds)

CVSS: 6.2EPSS: 0%CPEs: 2EXPL: 0

16 Mar 2021 — IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials. IBM X-Force ID: 190974. IBM Spectrum Scale versiones 5.0.0 hasta 5.0.5.5 y versiones 5.1.0 hasta 5.1.0.2, usa una configuración inadecuada de bloqueo de cuenta que podría permitir a un usuario local usar las credenciales de cuenta de la API Rest mediante fuerza bruta. IBM X-Force ID: 190974 • https://exchange.xforce.ibmcloud.com/vulnerabilities/190974 • CWE-307: Improper Restriction of Excessive Authentication Attempts •

CVSS: 4.4EPSS: 0%CPEs: 2EXPL: 0

16 Mar 2021 — IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user with a valid role to the REST API to cause a denial of service due to weak or absense of rate limiting. IBM X-Force ID: 190973. IBM Spectrum Scale versiones 5.0.0 hasta 5.0.5.5 y versiones 5.1.0 hasta 5.1.0.2, podría permitir a un usuario local con un rol válido en la API REST causar una denegación de servicio debido a una limitación de velocidad débil o ausente. IBM X-Force ID: 190973 • https://exchange.xforce.ibmcloud.com/vulnerabilities/190973 •

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

16 Mar 2021 — IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190450. IBM Spectrum Scale versiones 5.0.0 hasta 5.0.5.5 y versiones 5.1.0 hasta 5.1.0.2, podría permitir a un usuario local envenenar unos archivos de registro que podrían afectar los esfuerzos de soporte y desarrollo. IBM X-Force ID: 190450 • https://exchange.xforce.ibmcloud.com/vulnerabilities/190450 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVSS: 4.0EPSS: 0%CPEs: 3EXPL: 0

26 Jan 2021 — IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190971. IBM Spectrum Scale versiones 5.0.0 hasta 5.0.5.4 y versión 5.1.0, podría permitir a un usuario local envenene los archivos de registro que podrían afectar los esfuerzos de soporte y desarrollo. IBM X-Force ID: 190971 • https://exchange.xforce.ibmcloud.com/vulnerabilities/190971 •

CVSS: 6.2EPSS: 0%CPEs: 3EXPL: 0

20 Oct 2020 — IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service. IBM X-Force ID: 188599. IBM Spectrum Scale versiones V4.2.0.0 hasta V4.2.3.23 y versiones V5.0.0.0 hasta V5.0.5.2, así como IBM Elastic Storage System versiones 6.0.0 hasta 6.0.1.0, podrían permitir que un atacante local ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/188599 • CWE-404: Improper Resource Shutdown or Release •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

20 Oct 2020 — IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188595. IBM Spectrum Scale versiones 5.0.0 hasta 5.0.5.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/188595 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

20 Oct 2020 — IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 188518. IBM Spectrum Scale versiones 5.0.0 hasta 5.0.5.2 no establece el atributo seguro en tokens de autorización o cook... • https://exchange.xforce.ibmcloud.com/vulnerabilities/188518 • CWE-565: Reliance on Cookies without Validation and Integrity Checking •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

20 Oct 2020 — IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188517. IBM Spectrum Scale versiones 5.0.0 hasta 5.0.5.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/188517 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

20 Oct 2020 — IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial of service by sending a large number of RPC requests to the mmfsd daemon which would cause the service to crash. IBM X-Force ID: 181991. IBM Spectrum Scale versiones V4.2.0.0 hasta V4.2.3.22 y versiones V5.0.0.0 hasta V5.0.5, podría permitir a un atacante local causar una denegación de servicio al enviar una gran cantidad de peticiones RPC al demonio mmfsd que causaría el servicio se bloq... • https://exchange.xforce.ibmcloud.com/vulnerabilities/181991 •

CVSS: 6.2EPSS: 0%CPEs: 2EXPL: 0

31 Aug 2020 — IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device with invalid arguments. IBM X-Force ID: 181992. IBM Spectrum Scale versiones V5.0.0.0 hasta V5.0.4.3 y versiones V4.2.0.0 hasta V4.2.3.21, podría permitir a un atacante local causar una denegación de servicio bloqueando el kernel por medio del envío de un subconjunto de ioctls sobre el dispositivo con argumentos ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/181992 • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') •