CVE-2023-30434 – IBM Storage Scale denial of service
https://notcve.org/view.php?id=CVE-2023-30434
IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3.0 through 6.1.6.0) could allow a local user to cause a kernel panic. IBM X-Force ID: 252187. • https://exchange.xforce.ibmcloud.com/vulnerabilities/252187 https://www.ibm.com/support/pages/node/6988363 https://www.ibm.com/support/pages/node/6988365 • CWE-20: Improper Input Validation •
CVE-2020-4927 – IBM Spectrum Scale information disclosure
https://notcve.org/view.php?id=CVE-2020-4927
A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695. • https://exchange.xforce.ibmcloud.com/vulnerabilities/191695 https://www.ibm.com/support/pages/node/6960571 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2022-43869 – IBM Spectrum Scale denial of service
https://notcve.org/view.php?id=CVE-2022-43869
IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack. IBM X-Force ID: 239539. • https://exchange.xforce.ibmcloud.com/vulnerabilities/239539 https://www.ibm.com/support/pages/node/6909465 https://www.ibm.com/support/pages/node/6909469 • CWE-134: Use of Externally-Controlled Format String •
CVE-2022-40607 – IBM Spectrum Scale directory traversal
https://notcve.org/view.php?id=CVE-2022-40607
IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem. IBM X-Force ID: 235740. IBM Spectrum Scale 5.1 podría permitir a los usuarios con permisos para crear pods, volúmenes persistentes y reclamaciones de volumen persistentes acceder a archivos y directorios fuera del volumen, incluso en el sistema de archivos del host. ID de IBM X-Force: 235740. • https://exchange.xforce.ibmcloud.com/vulnerabilities/235740 https://www.ibm.com/support/pages/node/6848231 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2020-4926
https://notcve.org/view.php?id=CVE-2020-4926
A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600. Una vulnerabilidad en el componente core de Spectrum Scale 5.1 e IBM Elastic Storage System 6.1, podría permitir el acceso no autorizado a los datos del usuario o la inyección de datos arbitrarios en el protocolo de comunicación. IBM X-Force ID: 191600 • https://exchange.xforce.ibmcloud.com/vulnerabilities/191600 https://www.ibm.com/support/pages/node/6565399 https://www.ibm.com/support/pages/node/6589109 • CWE-862: Missing Authorization •