Vulnerability CVE-2016-5943


Published: 2016-09-26

Description:
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properties, via unspecified vectors.

Type:

CWE-284

(Improper Access Control)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.5/10
4.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
IBM -> Spectrum control 
IBM -> Tivoli storage productivity center 

 References:
http://www-01.ibm.com/support/docview.wss?uid=swg1IT16944
http://www-01.ibm.com/support/docview.wss?uid=swg21988625
http://www.securityfocus.com/bid/93084

Copyright 2024, cxsecurity.com

 

Back to Top