Known vulnerabilities in IBM Spectrum Scale

Software CPE: cpe:2.3:a:ibm_corporation:ibm_spectrum_scale:*:*:*:*:*:*:*:*
Total vulnerabilities: 34
Public exploits: 6
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Spectrum Scale IBM Spectrum Scale is affected by 34 known vulnerabilities: 10 high, 14 medium, 10 low Critical High Medium Low

Vulnerabilities (34)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU86988 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2023-50312
CWE-327 Low
No
No
5.1.9.3, 5.2.0.0 04.03.2024 SB2024030425
SB2024031819
SB2024032049
and 49 more
#VU84396 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2022-43843
CWE-327 Medium
No
No
5.1.9.1 13.12.2023 SB2023121342
#VU82978 - Exposure of sensitive information to an unauthorized actor
CVE-2023-45803
CWE-200 Medium
No
No
5.1.2.15, 5.1.9.1 10.11.2023 SB2023111038
SB2023111040
SB2023111048
and 122 more
#VU82350 - Resource Management Errors
CVE-2023-46158
CWE-399 Medium
No
No
5.1.2.15, 5.1.9.2 24.10.2023 SB2023102444
SB2023120144
SB2023122104
and 30 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
5.1.2.15, 5.1.9.2 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU81322 - Exposure of sensitive information to an unauthorized actor
CVE-2023-43804
CWE-200 Low
Available
No
5.1.2.15, 5.1.9.1 02.10.2023 SB2023100251
SB2023100259
SB2023100260
and 112 more
#VU73116 - Insufficient Verification of Data Authenticity
CVE-2020-4927
CWE-345 Medium
No
No
5.1.6.1, 5.1.7.0 08.03.2023 SB2023030802
SB2023070101
#VU71739 - Use of Externally-Controlled Format String
CVE-2022-43869
CWE-134 Medium
No
No
5.1.2.9, 5.1.6.0 01.02.2023 SB2023020145
SB2023020840
#VU70530 - Deserialization of Untrusted Data
CVE-2022-45047
CWE-502 High
Available
No
5.1.2.9, 5.1.7.0 28.12.2022 SB2022122828
SB2022122920
SB2023011148
and 49 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
5.1.2.10, 5.1.7.0 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU70334 - Allocation of Resources Without Limits or Throttling
CVE-2022-41717
CWE-770 Medium
Available
No
5.1.7.0 14.12.2022 SB2022121432
SB2022121433
SB2022121435
and 185 more
#VU69531 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-25168
CWE-78 High
No
No
5.1.5.1 23.11.2022 SB2022112314
SB2022112334
SB2022121525
and 10 more
#VU69209 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-34165
CWE-444 Medium
No
No
5.1.2.7, 5.1.6.0 10.11.2022 SB2022111029
SB2022111104
SB2022111409
and 58 more
#VU68701 - Heap-based Buffer Overflow
CVE-2022-3437
CWE-122 Low
No
No
5.1.6.1, 5.1.7.0 25.10.2022 SB2022102524
SB2022102558
SB2022102521
and 33 more
#VU67270 - Use of Insufficiently Random Values
CVE-2022-1615
CWE-330 Low
No
No
5.1.6.1, 5.1.7.0 13.09.2022 SB2022091371
SB2022091377
SB2022091448
and 18 more
#VU65845 - Authentication Bypass by Spoofing
CVE-2022-22476
CWE-290 Medium
No
No
5.1.2.7, 5.1.6.0 28.07.2022 SB2022072816
SB2022080903
SB2022082228
and 29 more
#VU62400 - Improper input validation
CVE-2022-21496
CWE-20 Medium
No
No
5.1.2.6, 5.1.4.1 19.04.2022 SB2022041944
SB2022041945
SB2022042102
and 118 more
#VU62401 - Improper input validation
CVE-2022-21434
CWE-20 Medium
No
No
5.1.2.6, 5.1.4.1 19.04.2022 SB2022041944
SB2022041945
SB2022042102
and 111 more
#VU59053 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-42550
CWE-94 Medium
No
No
5.1.6.1 19.12.2021 SB2021121904
SB2022022307
SB2022032929
and 21 more
#VU26418 - Deserialization of Untrusted Data
CVE-2017-5929
CWE-502 High
No
No
5.1.6.1 27.03.2020 SB2017031302
SB2020032701
SB2022101720
and 1 more


Showing elements 1 - 20 out of 34