CVE-2025-36104 PUBLISHED

IBM Storage Scale information disclosure

Assigner: ibm
Reserved: 15.04.2025 Published: 12.07.2025 Updated: 14.07.2025

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the SMB protocol.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor IBM
Product Storage Scale
Versions Default: unaffected
  • Version 5.2.3.0, 5.2.3.1 is affected

Solutions

For IBM Storage Scale 5.2.3.0 and 5.2.3.1, IBM strongly recommends addressing the vulnerability by upgrading to 5.2.3.2 or later: https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&produ... https://www.ibm.com/support/fixcentral/swg/selectFixes .

References

Problem Types

  • CWE-277 Insecure Inherited Permissions CWE