Sceawere

Vulnerability Detail

CVE-2026-19483UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Storage Scale GUI Secret Disclosure

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
2h ago
Vendor
IBM
Product
Storage Scale
Attack Type
CWE-532 Insertion of Sensitive Information into Log File
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade from GUI. Secrets may be disclosed in information related to exceptions in IBM Storage Scale Management GUI.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-13T21:17:46.003Z",
  "pubdate": "2026-08-13T21:17:46.003Z",
  "executiveSummary": "An information disclosure vulnerability has been identified within the IBM Storage Scale Management GUI, specifically impacting the Systems Deploy and Upgrade functionality as well as exception-handling routines. The root issue involves sensitive authentication secrets, notably the administrative password, being written in plaintext to application log files during routine operations and exception states. This security flaw enables unauthorized actors with read access to the affected log files to harvest administrative credentials. Successful exploitation compromises the confidentiality of administrative credentials, potentially leading to unauthorized system access, privilege escalation, and full administrative control over the targeted storage infrastructure. The vulnerability affects IBM Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0. Exploitation typically requires prior access to the underlying log files or systems generating the logs, presenting significant operational risk in multi-tenant or improperly permissioned environments. Remediation requires applying official vendor patches or updates as soon as they become available, alongside strict access control enforcement on log directories.",
  "technicalDetails": "The vulnerability resides in the IBM Storage Scale Management GUI component, specifically within the execution paths associated with the Systems Deploy and Upgrade from GUI feature and general exception-handling mechanisms. During the deployment or upgrade orchestration, or when runtime exceptions occur, sensitive parameters including administrative credentials are inadvertently passed to logging subsystems without proper sanitization or obfuscation. As a result, the cleartext admin password is persistently stored within the application's GUI log files. The vulnerable components process sensitive configuration strings and fail to redact authentication material before writing diagnostic and error output to disk. An attacker who has achieved local or network-based read access to the log storage locations can extract these exposed secrets. The attack flow generally proceeds as follows: first, the administrator initiates a deployment or upgrade action through the Management GUI, or an exception condition is triggered during GUI operations; second, the internal logging mechanism captures the execution state, serializing the plaintext administrator password into the log files; third, an unauthorized user or malicious actor accesses the log files via misconfigured file permissions, secondary vulnerabilities, or insider access; fourth, the actor retrieves the administrative password and leverages it to authenticate directly against the IBM Storage Scale Management GUI with elevated privileges. The affected software versions comprise IBM Storage Scale 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0. This issue exposes the system to compromise of administrative trust domains, requiring robust log segregation and permission hardening to mitigate unauthorized inspection."
}
CVE-2026-19483: IBM Storage Scale GUI Secret Disclosure (HIGH Severity, CVSS: 7.1) - Sceawere