CVE-2024-31891

IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host operating system.
References
Link Resource
https://www.ibm.com/support/pages/node/7178098 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:storage_scale:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_scale:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

25 Jul 2025, 20:57

Type Values Removed Values Added
First Time Linux linux Kernel
Ibm storage Scale
Ibm
Linux
Summary
  • (es) IBM Storage Scale GUI 5.1.9.0 a 5.1.9.6 y 5.2.0.0 a 5.2.1.1 contiene una vulnerabilidad de escalada de privilegios locales. Un actor malintencionado con acceso de línea de comandos al usuario 'scalemgmt' puede elevar los privilegios para obtener acceso raíz al sistema operativo host.
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_scale:*:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7178098 - () https://www.ibm.com/support/pages/node/7178098 - Vendor Advisory

14 Dec 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-14 13:15

Updated : 2025-07-25 20:57


NVD link : CVE-2024-31891

Mitre link : CVE-2024-31891

CVE.ORG link : CVE-2024-31891


JSON object : View

Products Affected

linux

  • linux_kernel

ibm

  • storage_scale
CWE
CWE-250

Execution with Unnecessary Privileges