Information disclosure in IBM Spectrum Scale - CVE-2017-1654

 

Information disclosure in IBM Spectrum Scale - CVE-2017-1654

Published: April 25, 2018 / Updated: April 25, 2018


Vulnerability identifier: #VU12149
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1654
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local unprivileged attacker to obtain potentially sensitive information.

The vulnerability exists due to a flaw in the IBM Spectrum Scale component. A local attacker can obtain potentially sensitive information from dump files and cause the information to be transferred to IBM during service engagements.


Affected software

IBM Spectrum Scale
IBM DB2
IBM DB2 LUW

How to mitigate CVE-2017-1654

Install update from vendor's website.


External References

Related Security Bulletins