Database/Control plane, storage & DevOps

IBM Spectrum Scale management GUI: Any authenticated GUI user - including a low-privilege monitoring account - runs
Impact
Any authenticated GUI user - including a low-privilege monitoring account - runs commands on the management node. That is full control of the storage management plane: filesets, quotas, exports and audit configuration for every tenant on the cluster.
Who can reach it
HTTP access to the Storage Scale GUI with any valid login. Typically the GUI is on the management network, so a foothold anywhere with management-network reach plus one weak GUI credential is sufficient.
What to do
Upgrade the GUI to the fixed 4.2/5.0 level named in IBM's bulletin. Separately, take the GUI off any network a tenant workload can route to, and cut back read-only GUI accounts that no longer need to exist.
References
Related entries
- AMD ATI atillk64.sys - physical memory mapping driver: The AMD ATI atillk64.sys driver exposes routines that mapCVE-2020-12138 · AMD ATI atillk64.sys - physical memory mapping driverHigh
- Intel Data Center Manager Console: Improper input validation in the DCM Console lets an authenticated user escalateCVE-2020-12347 · Intel Data Center Manager ConsoleHigh
- Marvell QConvergeConsole (QLogic adapter management): Remote code execution on QConvergeConsole, the managementCVE-2020-17389 · Marvell QConvergeConsole (QLogic adapter management)High
- Ceph CephX authentication protocol: CephX does not correctly bind client identity, so an attacker who can captureCVE-2020-25660 · Ceph CephX authentication protocolHigh
- APC PowerChute Business Edition (v9.0.x and earlier): PowerChute runs the shutdown script that fires when a UPS reportsCVE-2020-7526 · APC PowerChute Business Edition (v9.0.x and earlier)High
- Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1: Authenticated file uploadCVE-2020-7569 · Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.