CVE-2016-2984: High severity ibm spectrum scale vulnerability
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted command-line parameters to a /usr/lpp/mmfs/bin/ setuid program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2984?
CVE-2016-2984 has a medium severity rating, allowing local users to escalate privileges.
How do I fix CVE-2016-2984?
To fix CVE-2016-2984, upgrade IBM Spectrum Scale to version 4.1.1.8 or higher, or 4.2.0.4 or higher.
Which versions are affected by CVE-2016-2984?
CVE-2016-2984 affects IBM Spectrum Scale versions before 4.1.1.8 and 4.2.x before 4.2.0.4, as well as GPFS versions before 3.5.0.32.
Who is impacted by CVE-2016-2984?
Local users of the affected IBM Spectrum Scale and GPFS versions are most impacted by CVE-2016-2984.
What type of vulnerability is CVE-2016-2984?
CVE-2016-2984 is a privilege escalation vulnerability that can be exploited through crafted command-line parameters.