CVE-2016-0361
IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via…
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- ibm/general parallel file system
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21986595Patch, Vendor Advisory
- http://www.securityfocus.com/bid/90550
- http://www.securitytracker.com/id/1036455
- http://www-01.ibm.com/support/docview.wss?uid=swg21986595Patch, Vendor Advisory
- http://www.securityfocus.com/bid/90550
- http://www.securitytracker.com/id/1036455
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.