Description
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade from GUI. Secrets may be disclosed in information related to exceptions in IBM Storage Scale Management GUI.
Published: 2026-08-13
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows the IBM Storage Scale Management GUI to log sensitive secrets such as the admin password. When an administrator performs a login or deploys upgrades via the GUI, the credentials are written to log files, which can be accessed by users with system or application administrative privileges. This results in the disclosure of secrets and violates confidentiality.

Affected Systems

IBM Storage Scale installations running version 5.2.3.0 through 5.2.3.8 or 6.0.0.0 through 6.0.1.0 are affected. The vendor has addressed the issue in releases 5.2.3.9 and later for the 5.x line, and 6.0.1.1 and later for the 6.x line.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity of the vulnerability. While the EPSS score is not available, exploitation is possible if an attacker can read the GUI log files or has privileged access to the system. The vulnerability is not listed in the CISA KEV catalog, so it has not yet been reported as widely exploited. The risk is mitigated by applying the vendor‑provided fixes; without them, any actor with access to the logs could acquire administrative passwords.

Generated by OpenCVE AI on August 13, 2026 at 22:36 UTC.

Remediation

Vendor Solution

For IBM Storage Scale 5.2.3.x, IBM strongly recommends addressing the vulnerability by upgrading to 5.2.3.9 or later: https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Storage+Scale&release=5.2.3&platform=All&function=all For IBM Storage Scale 6.0.0.x, IBM strongly recommends addressing the vulnerability by upgrading to 6.0.1.1 or later: https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Storage+Scale&release=6.0.1&platform=All&function=all


OpenCVE Recommended Actions

  • Upgrade IBM Storage Scale 5.2.3.x installations to version 5.2.3.9 or later.
  • Upgrade IBM Storage Scale 6.0.0.x installations to version 6.0.1.1 or later.
  • Ensure log settings do not store credentials and restrict log file access to privileged administrators only.

Generated by OpenCVE AI on August 13, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade from GUI. Secrets may be disclosed in information related to exceptions in IBM Storage Scale Management GUI.
Title The following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higher
First Time appeared Ibm
Ibm storage Scale
Weaknesses CWE-532
CPEs cpe:2.3:a:ibm:storage_scale:5.2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_scale:5.2.3.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_scale:6.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_scale:6.0.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm storage Scale
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Storage Scale
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:47:01.247Z

Reserved: 2026-08-10T16:00:42.826Z

Link: CVE-2026-19483

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:46.003

Modified: 2026-08-13T21:17:46.003

Link: CVE-2026-19483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File