PT-2025-20606 · Ibm · Ibm Storage Scale

Published

2025-05-09

·

Updated

2025-08-12

·

CVE-2025-1137

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Storage Scale versions 5.2.2.0 through 5.2.2.1
Description The issue allows an authenticated user to execute privileged commands due to improper input neutralization. This is related to a command injection issue, specifically improper neutralization of special elements used in a command.
Recommendations For versions 5.2.2.0 and 5.2.2.1, consider restricting access to privileged commands until a patch is available. As a temporary workaround, avoid using configurations that allow authenticated users to execute commands with elevated privileges. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-08500
CVE-2025-1137

Affected Products

Ibm Storage Scale