CVE-2016-5946: Infoleak
Published Sep 26, 2016
·Updated
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
Affected Software
16 affected components
IBM Spectrum Control=5.2.8
IBM Spectrum Control=5.2.9
IBM Spectrum Control=5.2.10
IBM Spectrum Control=5.2.10.1
IBM Tivoli Storage Productivity Center=5.2.0
IBM Tivoli Storage Productivity Center=5.2.1
IBM Tivoli Storage Productivity Center=5.2.1.1
IBM Tivoli Storage Productivity Center=5.2.2
IBM Tivoli Storage Productivity Center=5.2.3
IBM Tivoli Storage Productivity Center=5.2.4
IBM Tivoli Storage Productivity Center=5.2.4.1
IBM Tivoli Storage Productivity Center=5.2.5
IBM Tivoli Storage Productivity Center=5.2.5.1
IBM Tivoli Storage Productivity Center=5.2.6
IBM Tivoli Storage Productivity Center=5.2.7
IBM Tivoli Storage Productivity Center=5.2.7.1
Remediation
Patch Available
Event History
Sep 26, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5946?
CVE-2016-5946 is classified as a high severity vulnerability due to its ability to allow unauthorized file access.
2
How do I fix CVE-2016-5946?
To fix CVE-2016-5946, upgrade IBM Spectrum Control to version 5.2.11 or later.
3
Who is affected by CVE-2016-5946?
CVE-2016-5946 affects certain versions of IBM Spectrum Control and IBM Tivoli Storage Productivity Center prior to 5.2.11.
4
What type of vulnerability is CVE-2016-5946?
CVE-2016-5946 is a directory traversal vulnerability that can be exploited by remote authenticated users.
5
Can CVE-2016-5946 lead to data exposure?
Yes, CVE-2016-5946 can lead to data exposure by allowing attackers to read arbitrary files on the server.