Home

Description

IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and modifying a csv file due to improper neutralization of formula elements.

PUBLISHED Reserved 2024-04-07 | Published 2024-12-14 | Updated 2024-12-16 | Assigner ibm




HIGH: 7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

5.1.9.0 (semver)
affected

5.2.0.0 (semver)
affected

References

www.ibm.com/support/pages/node/7178098 vendor-advisory

cve.org (CVE-2024-31892)

nvd.nist.gov (CVE-2024-31892)

Download JSON