Database/Control plane, storage & DevOps

IBM Spectrum Scale Data Access Services (DAS): An authenticated DAS user inserts code that manipulates cluster
Impact
An authenticated DAS user inserts code that manipulates cluster resources, because DAS runs with more permission than the caller should inherit. The user ends up changing shared cluster state rather than just their own data path.
Who can reach it
Any authenticated user of the Data Access Services layer in Spectrum Scale DAS 5.1.3.1 - typically the S3/object front end offered to tenants.
What to do
Upgrade DAS to the fixed level in IBM's bulletin and restart the service. Review which service account DAS runs as and tighten it so an escape yields less.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.