First published: Mon Aug 08 2016(Updated: )
IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM General Parallel File System | =3.5 | |
IBM General Parallel File System | =3.5.0.3 | |
IBM General Parallel File System | =3.5.0.7 | |
IBM General Parallel File System | =3.5.0.9 | |
IBM General Parallel File System | =3.5.0.11 | |
IBM General Parallel File System | =3.5.0.16 | |
IBM General Parallel File System | =4.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0361 is classified as a moderate severity vulnerability that allows remote authenticated users to access sensitive information.
To fix CVE-2016-0361, update IBM General Parallel File System to version 3.5.0.29 efix 6 or 4.1.1.4 efix 9.
CVE-2016-0361 affects IBM General Parallel File System versions 3.5 and 4.1.1 prior to the specified efix versions.
CVE-2016-0361 can potentially expose sensitive information related to administrative accounts.
Remote authenticated users on systems using affected versions of IBM General Parallel File System may be impacted by CVE-2016-0361.