6.2
CVE-2017-1304
- EPSS 0.07%
- Veröffentlicht 21.06.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle psirt@us.ibm.com
- Teams Watchlist Login
- Unerledigt Login
IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing of an unsupported configuration, where users applications are running on an active ESS I/O server node and utilize direct I/O to perform a read or a write to a Spectrum Scale file. This vulnerability may result in the use of an incorrect memory address, leading to a Spectrum Scale/GPFS daemon failure with a Signal 11, and possibly leading to denial of service or undetected data corruption. IBM X-Force ID: 125458.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Elastic Storage Server Version2.0.0
Ibm ≫ Elastic Storage Server Version2.5.0
Ibm ≫ Elastic Storage Server Version2.5.5
Ibm ≫ Elastic Storage Server Version3.0.0
Ibm ≫ Elastic Storage Server Version3.0.5
Ibm ≫ Elastic Storage Server Version3.5.0
Ibm ≫ Elastic Storage Server Version3.5.6
Ibm ≫ Elastic Storage Server Version4.0.0
Ibm ≫ Elastic Storage Server Version4.0.6
Ibm ≫ Elastic Storage Server Version4.5.0
Ibm ≫ Elastic Storage Server Version4.6.0
Ibm ≫ Elastic Storage Server Version5.0.0
Ibm ≫ Elastic Storage Server Version5.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.186 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.2 | 1.4 | 4.7 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.