First published: Fri Jul 08 2016(Updated: )
IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Control Center | =6.0.0.0 | |
IBM Sterling Control Center | =5.4.0.0 | |
IBM Sterling Control Center | =5.4.0.1 | |
IBM Sterling Control Center | =5.4.1 | |
IBM Sterling Control Center | =5.4.1.0 | |
IBM Sterling Control Center | =5.4.2 | |
IBM Sterling Control Center | =5.4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0252 has been assigned a medium severity rating.
To mitigate CVE-2016-0252, upgrade to IBM Control Center 6.0.0.1 iFix06 or Sterling Control Center 5.4.2.1 iFix09 or later.
CVE-2016-0252 affects local users of IBM Control Center version 6.0.0.0 and Sterling Control Center versions 5.4.0.0 through 5.4.2.0.
CVE-2016-0252 allows local users to decrypt the master key, potentially compromising sensitive data.
CVE-2016-0252 was announced in January 2016.