IBM Storage Scale Incorrect Permission Assignment Vulnerability Allowing Unintended Resource Execution
Vulnerability
A vulnerability exists in IBM Storage Scale versions 5.2.3.0 to 5.2.3.5 and 6.0.0.0 to 6.0.0.1. This vulnerability could enable a local user to unintentionally grant additional permissions for resources, allowing those resources to be executed by unintended actors. The issue arises when a directory has a specific Access Control List (ACL) composition that leads to improper execute permissions.
Impact
Exploitation of this vulnerability could result in unauthorized execution of resources by unintended actors.
Remediation
Users are advised to upgrade to IBM Storage Scale version 5.2.3.6 or 6.0.0.2. Instructions for downloading these versions are available on the IBM Support Fix Central website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
