CVE-2015-4974: Command Injection
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4974?
CVE-2015-4974 is considered a high severity vulnerability allowing local users to obtain root privileges.
How do I fix CVE-2015-4974?
To fix CVE-2015-4974, upgrade IBM General Parallel File System to version 3.5.0.27 or higher, or Spectrum Scale to version 4.1.1.2 or higher.
Who is affected by CVE-2015-4974?
CVE-2015-4974 affects local users of IBM General Parallel File System versions 3.5.x before 3.5.0.27 and Spectrum Scale 4.1.x before 4.1.1.2.
What types of systems are impacted by CVE-2015-4974?
Systems running vulnerable versions of IBM General Parallel File System and Spectrum Scale are impacted by CVE-2015-4974.
Is CVE-2015-4974 remote or local vulnerability?
CVE-2015-4974 is a local vulnerability, meaning it requires local access to exploit.