IBM Spectrum Fusion HCI improper access control
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 2.5%
exploitation probability
2.5%top 17% of all CVEs
observed exploitation
nono source reports it
In short
IBM Spectrum Fusion HCI versions 2.5.2 to 2.7.2 have a flaw that allows attackers to access storage buckets they shouldn't have permission to use. This could let unauthorized users read, modify, or delete data stored in the system.
Technical detail
The vulnerability exists in the Ceph RGW (RADOS Gateway) bucket access control implementation within IBM Spectrum Fusion HCI. An attacker can bypass authorization checks to perform unauthorized operations on buckets, potentially affecting data confidentiality and integrity. The flaw affects versions 2.5.2 through 2.7.2 due to improper access control validation.
Summary generated and translated by AI from the official description.
IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
Affected products
IBM · Spectrum Fusion HCI