CVE-2021-29671: Medium severity IBM Spectrum Scale vulnerability
Published Apr 8, 2021
·Updated
IBM Spectrum Scale 5.1.0.1 could allow a local attacker to bypass the filesystem audit logging mechanism when file audit logging is enabled. IBM X-Force ID: 199478.
Other sources
IBM Spectrum Scale could allow a local attacker to bypass the filesystem audit logging mechanism when file audit logging is enabled.
Affected Software
2 affected components
IBM Spectrum Scale>=5.1.0.1<5.1.0.2
IBM Spectrum Scale<=5.1.0.1
Remediation
Patch Available
Event History
Apr 8, 2021
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Apr 9, 2021
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-29671.
2
What is the severity of CVE-2021-29671?
The severity of CVE-2021-29671 is medium.
3
What is the affected software?
The affected software is IBM Spectrum Scale version 5.1.0.1.
4
How can a local attacker exploit this vulnerability?
A local attacker can bypass the filesystem audit logging mechanism when file audit logging is enabled.
5
Is there any additional information available?
Yes, you can find more information about this vulnerability at the following references: [1](https://exchange.xforce.ibmcloud.com/vulnerabilities/199478) [2](https://www.ibm.com/support/pages/node/6441429)