CVE-2016-0252: Infoleak
Published Jul 8, 2016
·Updated
IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors.
Affected Software
7 affected components
IBM Control Center=6.0.0.0
IBM Sterling Control Center=5.4.0.0
IBM Sterling Control Center=5.4.0.1
IBM Sterling Control Center=5.4.1
IBM Sterling Control Center=5.4.1.0
IBM Sterling Control Center=5.4.2
IBM Sterling Control Center=5.4.2.0
Event History
Jul 8, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0252?
CVE-2016-0252 has been assigned a medium severity rating.
2
How do I fix CVE-2016-0252?
To mitigate CVE-2016-0252, upgrade to IBM Control Center 6.0.0.1 iFix06 or Sterling Control Center 5.4.2.1 iFix09 or later.
3
Who is affected by CVE-2016-0252?
CVE-2016-0252 affects local users of IBM Control Center version 6.0.0.0 and Sterling Control Center versions 5.4.0.0 through 5.4.2.0.
4
What kind of attack does CVE-2016-0252 allow?
CVE-2016-0252 allows local users to decrypt the master key, potentially compromising sensitive data.
5
When was CVE-2016-0252 announced?
CVE-2016-0252 was announced in January 2016.