First published: Wed Feb 01 2017(Updated: )
IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Control | =5.2.8 | |
IBM Spectrum Control | =5.2.9 | |
IBM Spectrum Control | =5.2.10 | |
IBM Spectrum Control | =5.2.11 | |
IBM Tivoli Storage Productivity Center | =5.2.0 | |
IBM Tivoli Storage Productivity Center | =5.2.0.0 | |
IBM Tivoli Storage Productivity Center | =5.2.1.0 | |
IBM Tivoli Storage Productivity Center | =5.2.1.1 | |
IBM Tivoli Storage Productivity Center | =5.2.2.0 | |
IBM Tivoli Storage Productivity Center | =5.2.3.0 | |
IBM Tivoli Storage Productivity Center | =5.2.4.0 | |
IBM Tivoli Storage Productivity Center | =5.2.4.1 | |
IBM Tivoli Storage Productivity Center | =5.2.4.1_\+ | |
IBM Tivoli Storage Productivity Center | =5.2.5.0 | |
IBM Tivoli Storage Productivity Center | =5.2.5.1 | |
IBM Tivoli Storage Productivity Center | =5.2.6.0 | |
IBM Tivoli Storage Productivity Center | =5.2.7.0 | |
IBM Tivoli Storage Productivity Center | =5.2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-8942 is rated as medium risk due to a potential insider threat allowing limited unauthorized access.
To fix CVE-2016-8942, update IBM Tivoli Storage Productivity Center and IBM Spectrum Control to the latest patched version.
CVE-2016-8942 affects IBM Tivoli Storage Productivity Center versions 5.2.0 through 5.2.7.1 and IBM Spectrum Control versions 5.2.8 through 5.2.11.
No, CVE-2016-8942 requires an authenticated user with intimate knowledge of the system to exploit the vulnerability.
If exploited, CVE-2016-8942 could allow an authenticated user to modify system properties, potentially impacting system configuration and security.