CVE-2022-40607: IBM Spectrum Scale directory traversal
IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem. IBM X-Force ID: 235740.
Other sources
IBM Spectrum Scale could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-40607.
What is the severity level of CVE-2022-40607?
The severity level of CVE-2022-40607 is medium.
What software is affected by CVE-2022-40607?
IBM Spectrum Scale version 5.1.4.0 is affected by CVE-2022-40607.
What is the impact of CVE-2022-40607?
CVE-2022-40607 allows users with permissions to access files and directories outside of the volume, including on the host filesystem.
How can I fix CVE-2022-40607?
To fix CVE-2022-40607, upgrade to a version of IBM Spectrum Scale that is not affected by this vulnerability.