← back
CVE-2023-43040mediumCWE-1220

IBM Spectrum Fusion HCI improper access control

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 2.5%
exploitation probability
2.5%top 17% of all CVEs
observed exploitation
nono source reports it
In short

IBM Spectrum Fusion HCI versions 2.5.2 to 2.7.2 have a flaw that allows attackers to access storage buckets they shouldn't have permission to use. This could let unauthorized users read, modify, or delete data stored in the system.

Technical detail

The vulnerability exists in the Ceph RGW (RADOS Gateway) bucket access control implementation within IBM Spectrum Fusion HCI. An attacker can bypass authorization checks to perform unauthorized operations on buckets, potentially affecting data confidentiality and integrity. The flaw affects versions 2.5.2 through 2.7.2 due to improper access control validation.

Summary generated and translated by AI from the official description.
IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L