Vulnerabilities > IBM > General Parallel File System

DATE CVE VULNERABILITY TITLE RISK
2018-06-13 CVE-2018-1431 Unspecified vulnerability in IBM General Parallel File System and Spectrum Scale
A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node.
local
low complexity
ibm
4.6
2018-03-02 CVE-2017-1654 Information Exposure vulnerability in IBM General Parallel File System and Spectrum Scale
IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files.
local
low complexity
ibm CWE-200
2.1
2017-02-01 CVE-2016-6115 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM General Parallel File System and Spectrum Scale
IBM General Parallel File System is vulnerable to a buffer overflow.
network
low complexity
ibm CWE-119
critical
9.0
2016-11-25 CVE-2016-2985 Permissions, Privileges, and Access Controls vulnerability in IBM General Parallel File System and Spectrum Scale
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.
local
ibm CWE-264
6.9
2016-11-25 CVE-2016-2984 Permissions, Privileges, and Access Controls vulnerability in IBM General Parallel File System and Spectrum Scale
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted command-line parameters to a /usr/lpp/mmfs/bin/ setuid program.
local
ibm CWE-264
6.9
2016-08-08 CVE-2016-0361 Information Disclosure vulnerability in IBM Spectrum Scale
IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords.
network
low complexity
ibm
4.0
2016-01-02 CVE-2015-7403 Local Denial of Service vulnerability in IBM General Parallel File System and Spectrum Scale
IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors.
local
low complexity
ibm
2.1
2015-10-26 CVE-2015-4981 Information Exposure vulnerability in IBM General Parallel File System and Spectrum Scale
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors.
local
low complexity
ibm CWE-200
2.1
2015-10-26 CVE-2015-4974 Command Injection vulnerability in IBM General Parallel File System and Spectrum Scale
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.
local
low complexity
ibm CWE-77
7.2
2015-04-06 CVE-2015-1890 Information Exposure vulnerability in IBM General Parallel File System 4.1
/usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentially containing cleartext keys, and lacks a warning about reviewing this archive to detect included keys, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.
network
ibm CWE-200
3.5