IBM Spectrum Scale privilege escalation
CVE-2022-41739

7.9HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 April 2023

Summary

IBM Spectrum Scale, specifically the Container Native Storage Access versions 5.1.2.1 through 5.1.6.0, is affected by a vulnerability that may allow processes running in containers to bypass security measures designed to isolate them. This could potentially lead to unauthorized access to sensitive information on the host system, representing a significant risk for data security and integrity.

Affected Version(s)

Spectrum Scale Container Native Storage Access 5.1.2.1 < 5.1.6.0

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.