Known vulnerabilities in Storage Ceph 6.1z3

Software: Storage Ceph
Version: 6.1z3
Software CPE: cpe:2.3:a:ibm_corporation:storage_ceph:*:*:*:*:*:*:*:*
Total vulnerabilities: 41
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Storage Ceph version 6.1z3 Storage Ceph 6.1z3 is affected by 41 vulnerabilities: 3 high, 26 medium, 12 low Critical High Medium Low

Vulnerabilities (41)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118528 - Improper input validation
CVE-2024-47866
CWE-20 Medium
No
No
8.1z4 14.11.2025 SB2025111411
SB2025121914
SB2026020608
and 3 more
#VU113609 - Authorization Bypass Through User-Controlled Key
CVE-2024-10452
CWE-639 Low
No
No
7.1z3 04.08.2025 SB2025080425
SB2025080504
#VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-22871
CWE-444 Medium
No
No
8.1z2 05.04.2025 SB2025040507
SB2025040508
SB2025040739
and 109 more
#VU105984 - Inefficient Regular Expression Complexity
CVE-2025-27789
CWE-1333 Low
No
No
8.1 24.03.2025 SB2025032476
SB2025041020
SB2025041691
and 45 more
#VU105862 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-57965
CWE-79 Medium
No
No
8.1z1 19.03.2025 SB2025031916
SB2025031918
SB2025050262
and 14 more
#VU105461 - Resource exhaustion
CVE-2025-22868
CWE-400 Medium
No
No
8.1z2 10.03.2025 SB2025031013
SB2025031015
SB2025031076
and 89 more
#VU103932 - Missing release of memory after effective lifetime
CVE-2025-22866
CWE-401 Low
No
No
8.1z3 12.02.2025 SB20250212100
SB20250212101
SB20250212102
and 27 more
#VU103458 - Improper input validation
CVE-2025-22865
CWE-20 Medium
No
No
8.1 30.01.2025 SB2025013039
SB2025013045
SB2025072441
and 2 more
#VU103455 - Exposure of sensitive information to an unauthorized actor
CVE-2024-45336
CWE-200 Low
No
No
7.0z2 30.01.2025 SB2025013039
SB2025013043
SB2025013044
and 38 more
#VU102357 - Improper Authentication
CVE-2024-48916
CWE-287 High
No
No
7.1z4 06.01.2025 SB2025010643
SB2025010644
SB2025010702
and 11 more
#VU101868 - Resource exhaustion
CVE-2024-45338
CWE-400 Medium
No
No
8.1 19.12.2024 SB2024121932
SB2024123101
SB2025010619
and 137 more
#VU99566 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-49766
CWE-22 Medium
No
No
8.1 31.10.2024 SB2024103173
SB2024121313
SB2024121851
and 16 more
#VU97758 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2024-45801
CWE-1321 Medium
No
No
8.1 27.09.2024 SB2024092751
SB2024100823
SB2024100827
and 32 more
#VU88184 - Resource exhaustion
CVE-2023-45288
CWE-400 Medium
Public exploit available
No
7.0z2 05.04.2024 SB2024040533
SB2024040549
SB2024040551
and 189 more
#VU87197 - Resource exhaustion
CVE-2023-45290
CWE-400 Medium
No
No
8.1 07.03.2024 SB2024030734
SB2024030750
SB2024030752
and 101 more
#VU85240 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-11831
CWE-79 Medium
No
No
8.1z4 09.01.2024 SB2024010997
SB2025021411
SB2025021412
and 17 more
#VU84954 - Insufficient Verification of Data Authenticity
CVE-2023-46445
CWE-345 Medium
No
No
7.0z2 03.01.2024 SB2024010327
SB2024010328
SB2024020802
and 3 more
#VU84953 - Insufficient Verification of Data Authenticity
CVE-2023-46446
CWE-345 Medium
No
No
7.0z2 03.01.2024 SB2024010327
SB2024010328
SB2024020802
and 8 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Public exploit available
No
7.0z2 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU82064 - Resource exhaustion
CVE-2023-39325
CWE-400 Medium
No
No
7.1z4 16.10.2023 SB2023101651
SB2023101652
SB2023101653
and 341 more


Showing elements 1 - 20 out of 41