CVE-2016-0361
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21986595
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | general_parallel_file_system | 3.5 | |
| ibm | general_parallel_file_system | 3.5.0.3 | |
| ibm | general_parallel_file_system | 3.5.0.7 | |
| ibm | general_parallel_file_system | 3.5.0.9 | |
| ibm | general_parallel_file_system | 3.5.0.11 | |
| ibm | general_parallel_file_system | 3.5.0.16 | |
| ibm | general_parallel_file_system | 4.1.0.1 | |
References
Verify integrity in audit chain (admin only). AS-IS.