CVE-2015-7456: Infoleak
Published Jan 1, 2016
·Updated
IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows remote authenticated users to discover object-storage admin passwords via unspecified vectors.
Affected Software
4 affected components
IBM Spectrum Scale=4.1.1.0
IBM Spectrum Scale=4.1.1.1
IBM Spectrum Scale=4.1.1.2
IBM Spectrum Scale=4.2.2.0
Event History
Jan 1, 2016
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7456?
CVE-2015-7456 has a medium severity as it allows remote authenticated users to potentially discover sensitive admin passwords.
2
How do I fix CVE-2015-7456?
To fix CVE-2015-7456, update IBM Spectrum Scale to version 4.1.1.4 or 4.2.0.0 or later.
3
Which versions of IBM Spectrum Scale are affected by CVE-2015-7456?
CVE-2015-7456 affects IBM Spectrum Scale versions 4.1.1.0 through 4.1.1.2 and 4.2.2.0.
4
Who can exploit CVE-2015-7456?
CVE-2015-7456 can be exploited by remote authenticated users with access to the system.
5
What type of information can be exposed due to CVE-2015-7456?
CVE-2015-7456 can allow unauthorized access to object-storage admin passwords, compromising system security.