CVE-2024-31891: IBM Storage Scale
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host operating system.
Affected products
- IBM Storage Scale: from 5.1.9.0, before 5.1.9.7 (fixed in 5.1.9.7); from 5.2.0.0, before 5.2.2.0 (fixed in 5.2.2.0)
Published 2024-12-14. Last modified 2026-06-17.