Database/Control plane, storage & DevOps

IBM Spectrum Scale management GUI: Any authenticated GUI user - including a low-privilege monitoring account - runs
Impact
Any authenticated GUI user - including a low-privilege monitoring account - runs commands on the management node. That is full control of the storage management plane: filesets, quotas, exports and audit configuration for every tenant on the cluster.
Who can reach it
HTTP access to the Storage Scale GUI with any valid login. Typically the GUI is on the management network, so a foothold anywhere with management-network reach plus one weak GUI credential is sufficient.
What to do
Upgrade the GUI to the fixed 4.2/5.0 level named in IBM's bulletin. Separately, take the GUI off any network a tenant workload can route to, and cut back read-only GUI accounts that no longer need to exist.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.