PT-2025-20606 · Ibm · Ibm Storage Scale
Published
2025-05-09
·
Updated
2025-08-12
·
CVE-2025-1137
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Storage Scale versions 5.2.2.0 through 5.2.2.1
Description
The issue allows an authenticated user to execute privileged commands due to improper input neutralization. This is related to a command injection issue, specifically improper neutralization of special elements used in a command.
Recommendations
For versions 5.2.2.0 and 5.2.2.1, consider restricting access to privileged commands until a patch is available.
As a temporary workaround, avoid using configurations that allow authenticated users to execute commands with elevated privileges.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Storage Scale