First published: Mon Oct 26 2015(Updated: )
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM General Parallel File System Storage Server | =3.5 | |
IBM General Parallel File System Storage Server | =3.5.0.0 | |
IBM General Parallel File System Storage Server | =3.5.0.2 | |
IBM General Parallel File System Storage Server | =3.5.0.3 | |
IBM General Parallel File System Storage Server | =3.5.0.4 | |
IBM General Parallel File System Storage Server | =3.5.0.6 | |
IBM General Parallel File System Storage Server | =3.5.0.7 | |
IBM General Parallel File System Storage Server | =3.5.0.8 | |
IBM General Parallel File System Storage Server | =3.5.0.9 | |
IBM General Parallel File System Storage Server | =3.5.0.10 | |
IBM General Parallel File System Storage Server | =3.5.0.11 | |
IBM General Parallel File System Storage Server | =3.5.0.12 | |
IBM General Parallel File System Storage Server | =3.5.0.13 | |
IBM General Parallel File System Storage Server | =3.5.0.14 | |
IBM General Parallel File System Storage Server | =3.5.0.15 | |
IBM General Parallel File System Storage Server | =3.5.0.16 | |
IBM General Parallel File System Storage Server | =3.5.0.17 | |
IBM General Parallel File System Storage Server | =3.5.0.18 | |
IBM General Parallel File System Storage Server | =3.5.0.19 | |
IBM General Parallel File System Storage Server | =3.5.0.20 | |
IBM General Parallel File System Storage Server | =3.5.0.21 | |
IBM General Parallel File System Storage Server | =3.5.0.22 | |
IBM General Parallel File System Storage Server | =3.5.0.23 | |
IBM General Parallel File System Storage Server | =3.5.0.24 | |
IBM General Parallel File System Storage Server | =3.5.0.25 | |
IBM General Parallel File System Storage Server | =3.5.0.26 | |
IBM Spectrum Scale | =4.1.1.0 | |
IBM Spectrum Scale | =4.1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4974 is considered a high severity vulnerability allowing local users to obtain root privileges.
To fix CVE-2015-4974, upgrade IBM General Parallel File System to version 3.5.0.27 or higher, or Spectrum Scale to version 4.1.1.2 or higher.
CVE-2015-4974 affects local users of IBM General Parallel File System versions 3.5.x before 3.5.0.27 and Spectrum Scale 4.1.x before 4.1.1.2.
Systems running vulnerable versions of IBM General Parallel File System and Spectrum Scale are impacted by CVE-2015-4974.
CVE-2015-4974 is a local vulnerability, meaning it requires local access to exploit.