First published: Fri May 10 2019(Updated: )
A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES stack enabled that could allow sensitive data to be included with service snaps. IBM X-Force ID: 160011.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Scale | >=4.1.1.0<=4.1.1.22 | |
IBM Spectrum Scale | >=4.2.0.0<=4.2.3.13 | |
IBM Spectrum Scale | >=5.0.0.0<=5.0.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4259 is medium with a severity value of 5.5.
IBM Spectrum Scale versions 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 are affected by CVE-2019-4259.
The vulnerability in IBM Spectrum Scale related to CVE-2019-4259 is the inclusion of sensitive data with service snaps when CES stack is enabled.
To fix the vulnerability, IBM recommends upgrading to a fixed version of IBM Spectrum Scale or applying the necessary patch.
More information about CVE-2019-4259 can be found in the IBM X-Force ID: 160011 and the IBM support documentation.