CVE-2016-5947: Input Validation
Published Sep 26, 2016
·Updated
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
Affected Software
16 affected components
IBM Tivoli Storage Productivity Center=5.2.0
IBM Tivoli Storage Productivity Center=5.2.1
IBM Tivoli Storage Productivity Center=5.2.1.1
IBM Tivoli Storage Productivity Center=5.2.2
IBM Tivoli Storage Productivity Center=5.2.3
IBM Tivoli Storage Productivity Center=5.2.4
IBM Tivoli Storage Productivity Center=5.2.4.1
IBM Tivoli Storage Productivity Center=5.2.5
IBM Tivoli Storage Productivity Center=5.2.5.1
IBM Tivoli Storage Productivity Center=5.2.6
IBM Tivoli Storage Productivity Center=5.2.7
IBM Tivoli Storage Productivity Center=5.2.7.1
IBM Spectrum Control=5.2.8
IBM Spectrum Control=5.2.9
IBM Spectrum Control=5.2.10
IBM Spectrum Control=5.2.10.1
Remediation
Patch Available
Event History
Sep 26, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5947?
CVE-2016-5947 has a medium severity rating due to its potential for clickjacking attacks that compromise user interactions.
2
How do I fix CVE-2016-5947?
To remediate CVE-2016-5947, upgrading to IBM Spectrum Control version 5.2.11 or later is recommended.
3
Who is affected by CVE-2016-5947?
CVE-2016-5947 affects remote authenticated users of IBM Spectrum Control versions prior to 5.2.11.
4
What type of attack is associated with CVE-2016-5947?
CVE-2016-5947 is associated with clickjacking attacks, which can deceive users into inadvertently clicking on malicious links.
5
Is CVE-2016-5947 being actively exploited?
As of the latest information, there are no reports of active exploitation of CVE-2016-5947 in the wild.