Impact
The vulnerability allows the IBM Storage Scale Management GUI to log sensitive secrets such as the admin password. When an administrator performs a login or deploys upgrades via the GUI, the credentials are written to log files, which can be accessed by users with system or application administrative privileges. This results in the disclosure of secrets and violates confidentiality.
Affected Systems
IBM Storage Scale installations running version 5.2.3.0 through 5.2.3.8 or 6.0.0.0 through 6.0.1.0 are affected. The vendor has addressed the issue in releases 5.2.3.9 and later for the 5.x line, and 6.0.1.1 and later for the 6.x line.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of the vulnerability. While the EPSS score is not available, exploitation is possible if an attacker can read the GUI log files or has privileged access to the system. The vulnerability is not listed in the CISA KEV catalog, so it has not yet been reported as widely exploited. The risk is mitigated by applying the vendor‑provided fixes; without them, any actor with access to the logs could acquire administrative passwords.
OpenCVE Enrichment