GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale management GUI: Any authenticated GUI user - including a low-privilege monitoring account - runs

CVE-2019-4715Control plane, storage & DevOpscurated

Impact

Any authenticated GUI user - including a low-privilege monitoring account - runs commands on the management node. That is full control of the storage management plane: filesets, quotas, exports and audit configuration for every tenant on the cluster.

Who can reach it

HTTP access to the Storage Scale GUI with any valid login. Typically the GUI is on the management network, so a foothold anywhere with management-network reach plus one weak GUI credential is sufficient.

What to do

Upgrade the GUI to the fixed 4.2/5.0 level named in IBM's bulletin. Separately, take the GUI off any network a tenant workload can route to, and cut back read-only GUI accounts that no longer need to exist.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.