Database/Control plane, storage & DevOps

IBM Spectrum Scale administrative command path: A local unprivileged user becomes root on a Storage Scale node by
Impact
A local unprivileged user becomes root on a Storage Scale node by injecting parameters into an administrative code path. Root on a storage node means the node's entire filesystem namespace, keys and cluster credentials are exposed.
Who can reach it
Local shell on any node running Storage Scale 4.2.0.0-4.2.3.17 or 5.0.0.0-5.0.3.2. No network position needed.
What to do
Move to the fixed 4.2.3.18 / 5.0.3.3 level or later. Where an immediate upgrade is not possible, remove interactive shell access for non-admin users on storage and NSD server nodes.
References
Related entries
- targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)CVE-2020-10699 · targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)High
- IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions): With specific debug settings enabled, LSFCVE-2020-4278 · IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions)High
- IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials): A user who is merely allowed to submit LSF jobsCVE-2020-4983 · IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials)High
- AMD System Management Unit (SMU) mailbox interface: A malicious user can manipulate SMU mailbox entries and reachCVE-2021-26331 · AMD System Management Unit (SMU) mailbox interfaceHigh
- Linux iSCSI: iSCSI netlink structures lack length checksCVE-2021-27365 · Linux iSCSIHigh
- IBM Spectrum Scale core component (format string handling): A user with a shell on any node that runs Storage ScaleCVE-2021-29740 · IBM Spectrum Scale core component (format string handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.