CVE-2018-1723: Infoleak
IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2 could allow an unprivileged, authenticated user with access to a GPFS node to read arbitrary files available on this node. IBM X-Force ID: 147373.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1723?
CVE-2018-1723 is considered to have a moderate severity level due to the potential for unauthorized file access by authenticated users.
How do I fix CVE-2018-1723?
To fix CVE-2018-1723, upgrade IBM Spectrum Scale to a version later than 4.1.1.20, 4.2.3.10, or 5.0.1.2.
Which versions of IBM Spectrum Scale are affected by CVE-2018-1723?
IBM Spectrum Scale versions 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0, and 5.0.1.2 are affected by CVE-2018-1723.
Can CVE-2018-1723 be exploited remotely?
No, CVE-2018-1723 requires an authenticated, unprivileged user with access to a GPFS node to exploit the vulnerability.
What type of files can be accessed due to CVE-2018-1723?
CVE-2018-1723 allows an unprivileged, authenticated user to read arbitrary files available on the GPFS node.