First published: Wed Feb 08 2023(Updated: )
IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack. IBM X-Force ID: 239539.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Elastic Storage System | >=6.1.0.0<=6.1.2.4 | |
IBM Elastic Storage System | >=6.1.3.0<=6.1.4.1 | |
IBM Spectrum Scale | >=5.1.0.0<=5.1.2.8 | |
IBM Spectrum Scale | >=5.1.3.0<=5.1.5.1 | |
Linux Linux kernel | ||
IBM Spectrum Scale | <=5.1.0.0 - 5.1.2.8 | |
IBM Spectrum Scale | <=5.1.3.0 - 5.1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43869 is a vulnerability that allows an authenticated user to cause a denial of service through the GUI using a format string attack in IBM Spectrum Scale and IBM Elastic Storage System.
IBM Spectrum Scale versions 5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1 are affected by CVE-2022-43869.
IBM Elastic Storage System versions 6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1 are affected by CVE-2022-43869.
An authenticated user can exploit CVE-2022-43869 by using a format string attack through the GUI.
CVE-2022-43869 has a severity rating of 6.5 (medium).