Improper Authentication in IBM Spectrum Scale - CVE-2022-22411
Published: August 5, 2022
Vulnerability identifier: #VU66133
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22411
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass authentication process.
The vulnerability exists due to service account token configured with risky permission. A remote user can bypass authentication process and gain unauthorized access to the application.
Affected software
IBM Spectrum Scale
Spectrum Scale Data Access Services (DAS)
Spectrum Scale Data Access Services (DAS)
How to mitigate CVE-2022-22411
Install updates from vendor's website.
IBM Spectrum Scale - update to 5.1.4
Spectrum Scale Data Access Services (DAS) - update to 5.1.4
Spectrum Scale Data Access Services (DAS) - update to 5.1.4