CVE-2016-5943: Medium severity ibm spectrum control vulnerability
Published Sep 26, 2016
·Updated
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properties, via unspecified vectors.
Affected Software
16 affected components
IBM Spectrum Control=5.2.0
IBM Spectrum Control=5.2.1
IBM Spectrum Control=5.2.1.1
IBM Spectrum Control=5.2.2
IBM Spectrum Control=5.2.3
IBM Spectrum Control=5.2.4
IBM Spectrum Control=5.2.4.1
IBM Spectrum Control=5.2.5
IBM Spectrum Control=5.2.5.1
IBM Spectrum Control=5.2.6
IBM Spectrum Control=5.2.7
IBM Spectrum Control=5.2.7.1
IBM Spectrum Control=5.2.8
IBM Spectrum Control=5.2.9
IBM Spectrum Control=5.2.10
IBM Spectrum Control=5.2.10.1
Remediation
Patch Available
Event History
Sep 26, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5943?
CVE-2016-5943 is rated as a moderate severity vulnerability.
2
How do I fix CVE-2016-5943?
To fix CVE-2016-5943, upgrade to IBM Spectrum Control version 5.2.11 or later.
3
What are the impacts of CVE-2016-5943?
CVE-2016-5943 allows remote authenticated users to bypass access restrictions, potentially leading to unauthorized access to sensitive task details.
4
Which versions of IBM Spectrum Control are affected by CVE-2016-5943?
Affected versions of IBM Spectrum Control include all 5.2.x versions prior to 5.2.11.
5
Who is affected by CVE-2016-5943?
Organizations using vulnerable versions of IBM Spectrum Control are at risk if they allow remote authenticated user access.