Check CVE Id
Check CWE Id
A security vulnerability has been identified in all levels of IBM Spectrum Scale V18.104.22.168 through V22.214.171.124 and IBM Spectrum Scale V126.96.36.199 through V188.8.131.52 that could allow a local attacker to obtain root privilege by injecting parameters into setuid files.
A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES stack enabled that could allow sensitive data to be included with service snaps. IBM X-Force ID: 160011.
IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.
IBM GPFS (IBM Spectrum Scale 184.108.40.206, 220.127.116.11, 18.104.22.168, 22.214.171.124, 5.0.0 and 126.96.36.199) command line utility allows an unprivileged, authenticated user with access to a GPFS node to forcefully terminate GPFS and deny access to data available through GPFS. IBM X-Force ID: 148806.
IBM Spectrum Scale 188.8.131.52, 184.108.40.206, 220.127.116.11, 18.104.22.168, 5.0.0 and 22.214.171.124 could allow an unprivileged, authenticated user with access to a GPFS node to read arbitrary files available on this node. IBM X-Force ID: 147373.
IBM GPFS (IBM Spectrum Scale 126.96.36.199 and 188.8.131.52) allows a local, unprivileged user to cause a kernel panic on a node running GPFS by accessing a file that is stored on a GPFS file system with mmap, or by executing a crafted file stored on a GPFS file system. IBM X-Force ID: 148805.
A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID: 139240.
IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.
IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash.
IBM Spectrum Scale 4.1.1.x before 184.108.40.206 and 4.2.x before 220.127.116.11 and General Parallel File System (GPFS) 3.5.x before 18.104.22.168 and 4.1.x before 22.214.171.124 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.
Back to Top