CVE-2020-4748
https://notcve.org/view.php?id=CVE-2020-4748
IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188517. IBM Spectrum Scale versiones 5.0.0 hasta 5.0.5.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando así la funcionalidad prevista conllevando a una divulgación de credenciales dentro de una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/188517 https://www.ibm.com/support/pages/node/6349449 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-4491
https://notcve.org/view.php?id=CVE-2020-4491
IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial of service by sending a large number of RPC requests to the mmfsd daemon which would cause the service to crash. IBM X-Force ID: 181991. IBM Spectrum Scale versiones V4.2.0.0 hasta V4.2.3.22 y versiones V5.0.0.0 hasta V5.0.5, podría permitir a un atacante local causar una denegación de servicio al enviar una gran cantidad de peticiones RPC al demonio mmfsd que causaría el servicio se bloquee. IBM X-Force ID: 181991 • https://exchange.xforce.ibmcloud.com/vulnerabilities/181991 https://www.ibm.com/support/pages/node/6349465 •
CVE-2020-4492
https://notcve.org/view.php?id=CVE-2020-4492
IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device with invalid arguments. IBM X-Force ID: 181992. IBM Spectrum Scale versiones V5.0.0.0 hasta V5.0.4.3 y versiones V4.2.0.0 hasta V4.2.3.21, podría permitir a un atacante local causar una denegación de servicio bloqueando el kernel por medio del envío de un subconjunto de ioctls sobre el dispositivo con argumentos no válidos. IBM X-Force ID: 181992 • https://exchange.xforce.ibmcloud.com/vulnerabilities/181992 https://www.ibm.com/support/pages/node/6324249 • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') •
CVE-2020-4379
https://notcve.org/view.php?id=CVE-2020-4379
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179158. IBM Spectrum Scale versiones 5.0.0.0 hasta 5.0.4.4, usa algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. IBM X-Force ID: 179158. • https://exchange.xforce.ibmcloud.com/vulnerabilities/179158 https://www.ibm.com/support/pages/node/6214483 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2020-4378
https://notcve.org/view.php?id=CVE-2020-4378
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions using a specially crated HTTP POST command. IBM X-Force ID: 179157. IBM Spectrum Scale versiones 5.0.0.0 hasta 5.0.4.4, podría permitir a un usuario autentificado privilegiado llevar a cabo acciones no autorizadas usando un comando HTTP POST especialmente diseñado. IBM X-Force ID: 179157. • https://exchange.xforce.ibmcloud.com/vulnerabilities/179157 https://www.ibm.com/support/pages/node/6214484 •