Executive brief
IBM Storage Scale is enterprise storage management software that administrators use to deploy and manage storage systems. A vulnerability allows admin passwords and other secrets to be written to unencrypted log files, where local users with log access can read them and compromise cluster security or gain elevated privileges.
Technical details
The vulnerability is a sensitive information disclosure flaw (CWE-532) in IBM Storage Scale Management GUI. Admin passwords and other secrets related to system deployment and upgrade operations are written in clear text to local GUI log files. An attacker with local access and low privileges can read these logs to extract credentials. The vulnerability affects Storage Scale versions 5.2.3.0–5.2.3.8 and 6.0.0.0–6.0.1.0. IBM has patched the issue in versions 5.2.3.9 and 6.0.1.1 or later.
Affected products
- IBM Storage Scale 5.2.3.0 through 5.2.3.8, 6.0.0.0 through 6.0.1.0
Timeline
- 2026-08-13: disclosed
- 2026-08-11: patched