IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Ibm Storage_Scale
cpe:2.3:a:ibm:storage_scale:*:*:*:*:*:*:*:*
|
5.2.3.0
|
5.2.3.9
|
|
Ibm Storage_Scale
cpe:2.3:a:ibm:storage_scale:*:*:*:*:*:*:*:*
|
6.0.0.0
|
6.0.1.1
|
|
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
|
— | — |