Unauthorized Actions possible due to CSV File Modification
CVE-2024-31892
7.5HIGH
Summary
A vulnerability exists in specific versions of IBM Storage Scale GUI that allows unauthorized actions by intercepting and modifying CSV files. This issue arises due to improper neutralization of formula elements, potentially enabling malicious users to exploit the system through crafted CSV content. The affected versions range from 5.1.9.0 to 5.1.9.6 and 5.2.0.0 to 5.2.1.1, highlighting the need for immediate attention to mitigate potential security risks.
Affected Version(s)
Storage Scale 5.1.9.0 <= 5.1.9.6
Storage Scale 5.2.0.0 <= 5.2.1.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved