First published: Mon Sep 26 2016(Updated: )
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properties, via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Control | =5.2.0 | |
IBM Spectrum Control | =5.2.1 | |
IBM Spectrum Control | =5.2.1.1 | |
IBM Spectrum Control | =5.2.2 | |
IBM Spectrum Control | =5.2.3 | |
IBM Spectrum Control | =5.2.4 | |
IBM Spectrum Control | =5.2.4.1 | |
IBM Spectrum Control | =5.2.5 | |
IBM Spectrum Control | =5.2.5.1 | |
IBM Spectrum Control | =5.2.6 | |
IBM Spectrum Control | =5.2.7 | |
IBM Spectrum Control | =5.2.7.1 | |
IBM Spectrum Control | =5.2.8 | |
IBM Spectrum Control | =5.2.9 | |
IBM Spectrum Control | =5.2.10 | |
IBM Spectrum Control | =5.2.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5943 is rated as a moderate severity vulnerability.
To fix CVE-2016-5943, upgrade to IBM Spectrum Control version 5.2.11 or later.
CVE-2016-5943 allows remote authenticated users to bypass access restrictions, potentially leading to unauthorized access to sensitive task details.
Affected versions of IBM Spectrum Control include all 5.2.x versions prior to 5.2.11.
Organizations using vulnerable versions of IBM Spectrum Control are at risk if they allow remote authenticated user access.