Database/Control plane, storage & DevOps

IBM Storage Scale session management: An authenticated user steals or fixates another user's active session and
CVE-2023-38002Control plane, storage & DevOpscurated
Impact
An authenticated user steals or fixates another user's active session and inherits their rights. If the victim is a storage administrator, the attacker owns the management plane for the whole cluster.
Who can reach it
Any authenticated user of Storage Scale 5.1.0.0 through 5.1.9.2 who can reach the session-bearing interface. No admin role needed as a starting point.
What to do
Upgrade to 5.1.9.3 or later. After upgrading, invalidate all existing sessions and force re-authentication - the fix does not retire sessions that were already fixated.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.