PT-2018-13956 · Ibm · Ibm Spectrum Scale

Published

2018-10-05

·

Updated

2019-10-09

·

CVE-2018-1723

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Spectrum Scale versions 4.1.1.0 through 4.1.1.20 IBM Spectrum Scale versions 4.2.0.0 through 4.2.3.10 IBM Spectrum Scale versions 5.0.0 through 5.0.1.2
Description The issue allows an unprivileged, authenticated user with access to a GPFS node to read arbitrary files available on this node.
Recommendations For IBM Spectrum Scale versions 4.1.1.0 through 4.1.1.20, update to a version that includes the fix for this issue. For IBM Spectrum Scale versions 4.2.0.0 through 4.2.3.10, update to a version that includes the fix for this issue. For IBM Spectrum Scale versions 5.0.0 through 5.0.1.2, update to a version that includes the fix for this issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1723

Affected Products

Ibm Spectrum Scale