Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Powerscale_onefs | Dell | 8.2.2.0 (including) | 9.7.1.2 (excluding) |
Powerscale_onefs | Dell | 9.8.0.0 (including) | 9.8.0.0 (including) |