5 results (0.009 seconds)

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

10 May 2025 — IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper input neutralization. • https://www.ibm.com/support/pages/node/7233085 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

31 Jul 2023 — IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.6.1 could allow a local user to obtain escalated privileges on a host without proper security context settings configured. IBM X-Force ID: 238941. IBM Storage Scale Container Native Storage Access de la versión 5.1.2.1 a la versión 5.1.6.1 podría permitir a un usuario local obtener privilegios escalados en un host sin la configuración de contexto de seguridad adecuada. ID de IBM X-Force: 238941. • https://exchange.xforce.ibmcloud.com/vulnerabilities/238941 •

CVSS: 8.4EPSS: 0%CPEs: 2EXPL: 0

29 Apr 2023 — IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that could allow a local user to obtain root privileges. IBM X-Force ID: 237810. • https://exchange.xforce.ibmcloud.com/vulnerabilities/237810 •

CVSS: 8.4EPSS: 0%CPEs: 1EXPL: 0

26 Apr 2023 — IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs running inside the container to overcome isolation mechanism and gain additional capabilities or access sensitive information on the host. IBM X-Force ID: 237815. • https://exchange.xforce.ibmcloud.com/vulnerabilities/237815 •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

06 Dec 2022 — IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437. IBM Spectrum Scale v5.1.0.1 a v5.1.4.1 podría permitir que un atacante local ejecute comandos arbitrarios en el contenedor. ID de IBM X-Force: 239437. • https://exchange.xforce.ibmcloud.com/vulnerabilities/239437 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •