Vulnerability Name:

CVE-2018-1993 (CCN-154440)

Assigned:2017-12-13
Published:2019-01-03
Updated:2019-10-09
Summary:IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.
CVSS v3 Severity:3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2018-1993

Source: CCN
Type: IBM Security Bulletin 0794443 (Elastic Storage Server)
IBM Spectrum Scale for IBM Elastic Storage Server is affected by the use of Local Read Only Cache (LROC) which may result in directory corruption and undetected data corruption in regular files.

Source: BID
Type: Third Party Advisory, VDB Entry
106485

Source: XF
Type: UNKNOWN
ibm-gpfs-cve20181993-info-disc(154440)

Source: XF
Type: VDB Entry, Vendor Advisory
ibm-gpfs-cve20181993-info-disc(154440)

Source: CCN
Type: IBM Security Bulletin 793719 (Spectrum Scale)
A vulnerability has been identified in IBM Spectrum Scale where the use of Local Read Only Cache (LROC) may result in directory corruption and undetected data corruption in regular files.

Source: CONFIRM
Type: Patch, Vendor Advisory
https://www.ibm.com/support/docview.wss?uid=ibm10793719

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:spectrum_scale:*:*:*:*:*:*:*:* (Version >= 4.1.1.0 and <= 4.1.1.21)
  • OR cpe:/a:ibm:spectrum_scale:*:*:*:*:*:*:*:* (Version >= 4.2.0.0 and <= 4.2.3.11)
  • OR cpe:/a:ibm:spectrum_scale:*:*:*:*:*:*:*:* (Version >= 5.0.0.0 and <= 5.0.2.0)

  • Configuration CCN 1:
  • cpe:/a:ibm:spectrum_scale:4.1.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_scale:4.2.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_scale:4.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_scale:4.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_scale:4.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_scale:5.0.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:elastic_storage_server:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:elastic_storage_server:4.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:elastic_storage_server:4.0.6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm spectrum scale *
    ibm spectrum scale *
    ibm spectrum scale *
    ibm spectrum scale 4.1.1.0
    ibm spectrum scale 4.2.0.0
    ibm spectrum scale 4.2.1
    ibm spectrum scale 4.2.2
    ibm spectrum scale 4.2.3
    ibm spectrum scale 5.0.0
    ibm elastic storage server 2.0
    ibm elastic storage server 4.0.0
    ibm elastic storage server 4.0.6