Known vulnerabilities in IBM Elastic Storage System

Software CPE: cpe:2.3:a:ibm_corporation:ibm_elastic_storage_system:*:*:*:*:*:*:*:*
Total vulnerabilities: 51
Public exploits: 7
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Elastic Storage System IBM Elastic Storage System is affected by 51 known vulnerabilities: 4 high, 21 medium, 26 low Critical High Medium Low

Vulnerabilities (51)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU88977 - Resource exhaustion
CVE-2024-25026
CWE-400 Medium
No
No
6.1.9.4 24.04.2024 SB2024042458
SB2024042525
SB2024042626
and 68 more
#VU88803 - Server-Side Request Forgery (SSRF)
CVE-2024-22329
CWE-918 Medium
No
No
6.1.9.4 18.04.2024 SB2024041812
SB2024042613
SB2024043016
and 67 more
#VU81437 - Memory corruption
CVE-2023-4911
CWE-119 Low
Available
Exploited
6.1.2.8, 6.1.8.3 03.10.2023 SB2023100343
SB2023100345
SB2023100402
and 94 more
#VU78413 - Improper input validation
CVE-2023-22045
CWE-20 Low
No
No
6.1.2.8, 6.1.9.0 19.07.2023 SB2023071985
SB2023071986
SB2023071987
and 155 more
#VU76906 - Out-of-bounds read
CVE-2023-2597
CWE-125 High
No
No
6.1.2.8, 6.1.9.0 05.06.2023 SB2023060525
SB2023060705
SB2023060930
and 86 more
#VU75807 - Use After Free
CVE-2023-32233
CWE-416 Low
Available
No
6.1.2.8, 6.1.8.3 09.05.2023 SB2023050923
SB2023051402
SB2023053054
and 100 more
#VU75323 - Out-of-bounds read
CVE-2023-2124
CWE-125 Low
No
No
6.1.2.8, 6.1.8.3 19.04.2023 SB2023041913
SB2023050422
SB2023051052
and 80 more
#VU75264 - Improper input validation
CVE-2023-21939
CWE-20 Medium
Available
No
6.1.2.8, 6.1.9.0 18.04.2023 SB20230418166
SB20230418167
SB2023041942
and 179 more
#VU75265 - Improper input validation
CVE-2023-21938
CWE-20 Low
No
No
6.1.2.8, 6.1.9.0 18.04.2023 SB20230418166
SB20230418167
SB2023041942
and 181 more
#VU75266 - Improper input validation
CVE-2023-21968
CWE-20 Low
No
No
6.1.2.8, 6.1.9.0 18.04.2023 SB20230418166
SB20230418167
SB2023041942
and 179 more
#VU75267 - Improper input validation
CVE-2023-21937
CWE-20 Low
No
No
6.1.2.8, 6.1.9.0 18.04.2023 SB20230418166
SB20230418167
SB2023041942
and 184 more
#VU75260 - Improper input validation
CVE-2023-21930
CWE-20 Medium
No
No
6.1.2.8, 6.1.9.0 18.04.2023 SB20230418166
SB20230418167
SB2023041942
and 191 more
#VU75261 - Improper input validation
CVE-2023-21967
CWE-20 Medium
No
No
6.1.2.8, 6.1.9.0 18.04.2023 SB20230418166
SB20230418167
SB2023041942
and 189 more
#VU75262 - Improper input validation
CVE-2023-21954
CWE-20 Medium
No
No
6.1.2.8, 6.1.9.0 18.04.2023 SB20230418166
SB20230418167
SB2023041942
and 166 more
#VU74771 - Information Exposure through Microarchitectural State after Transient Execution
CVE-2023-1637
CWE-1342 Low
No
No
6.1.2.8, 6.1.8.3 10.04.2023 SB2023041037
SB2023041041
SB2023041830
and 30 more
#VU74628 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2023-28466
CWE-362 Low
No
No
6.1.2.8, 6.1.8.3 10.04.2023 SB2023041032
SB2023041040
SB2023041041
and 79 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
6.1.2.7, 6.1.8.2 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU61246 - Use After Free
CVE-2021-4083
CWE-416 Low
No
No
6.0.2.6, 6.1.2.3, 6.1.3.0 10.03.2022 SB2022031029
SB2022031033
SB2022031034
and 55 more
#VU59970 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVE-2021-39031
CWE-90 Medium
No
No
6.0.2.6, 6.1.2.3, 6.1.3.0 25.01.2022 SB2022012506
SB2022032317
SB2022041207
and 12 more
#VU59719 - Improper input validation
CVE-2022-21291
CWE-20 Medium
No
No
6.0.2.6, 6.1.2.3, 6.1.3.0 18.01.2022 SB2022011840
SB2022011841
SB2022011931
and 67 more


Showing elements 1 - 20 out of 51