CVE-2017-1654: Infoleak
Published Mar 2, 2018
·Updated
IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.
Affected Software
15 affected components
IBM Spectrum Scale>=4.1.1.0<=4.1.1.18
IBM Spectrum Scale>=4.2.0.0<=4.2.0.4
IBM Spectrum Scale>=4.2.1.0<=4.2.1.2
IBM Spectrum Scale>=4.2.2.0<=4.2.2.3
IBM Spectrum Scale>=4.2.3.0<=4.2.3.6
IBM Spectrum Scale=5.0.0.0
IBM General Parallel File System=4.1.0.0
IBM General Parallel File System=4.1.0.1
IBM General Parallel File System=4.1.0.2
IBM General Parallel File System=4.1.0.3
IBM General Parallel File System=4.1.0.4
IBM General Parallel File System=4.1.0.5
IBM General Parallel File System=4.1.0.6
IBM General Parallel File System=4.1.0.7
IBM General Parallel File System=4.1.0.8
Remediation
Patch Available
Event History
Mar 2, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1654?
CVE-2017-1654 has a medium severity rating due to its potential impact on local user data exposure.
2
How do I fix CVE-2017-1654?
To mitigate CVE-2017-1654, upgrade IBM Spectrum Scale to version 4.2.4 or later.
3
Who is affected by CVE-2017-1654?
CVE-2017-1654 affects users of IBM Spectrum Scale versions 4.1.1 to 4.2.3 and IBM General Parallel File System 4.1.0.0 to 4.1.0.8.
4
What type of vulnerability is CVE-2017-1654?
CVE-2017-1654 is a local information disclosure vulnerability allowing unauthorized access to dump files.
5
Can CVE-2017-1654 lead to data exposure?
Yes, CVE-2017-1654 could allow unprivileged local users to access sensitive information from dump files.