PT-2022-15414 · Ibm · Ibm Spectrum Scale Data Access Services
Published
2022-08-10
·
Updated
2023-08-08
·
CVE-2022-22411
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Scale Data Access Services (DAS) version 5.1.3.1
Description
The issue allows an authenticated user to insert code, potentially enabling the attacker to manipulate cluster resources due to excessive permissions.
Recommendations
For IBM Spectrum Scale Data Access Services (DAS) version 5.1.3.1, consider restricting access to cluster resources to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Scale Data Access Services