CVE-2016-2985: High severity ibm spectrum scale vulnerability
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2985?
CVE-2016-2985 has a medium severity rating, highlighting the potential for local privilege escalation.
How do I fix CVE-2016-2985?
To fix CVE-2016-2985, upgrade IBM Spectrum Scale to version 4.1.1.8 or later, or 4.2.0.4 or later, or GPFS to version 3.5.0.32 or later.
Who is affected by CVE-2016-2985?
CVE-2016-2985 affects local users of IBM Spectrum Scale versions prior to 4.1.1.8 and 4.2.0.4, and General Parallel File System versions prior to 3.5.0.32.
What type of vulnerability is CVE-2016-2985?
CVE-2016-2985 is a local privilege escalation vulnerability involving crafted environment variables.
What versions of IBM Spectrum Scale are vulnerable in CVE-2016-2985?
IBM Spectrum Scale versions 4.1.1.0 through 4.1.1.7 and 4.2.0.0 through 4.2.0.3 are vulnerable as per CVE-2016-2985.