PT-2016-5272 · Ibm · Ibm Spectrum Protect

Publicado

2016-07-03

·

Atualizado

2017-09-01

·

CVE-2016-2894

CVSS v3.1

2.5

Baixa

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect versions 5.5 through 6.3 before 6.3.2.6 IBM Spectrum Protect versions 6.4 before 6.4.3.3 IBM Spectrum Protect versions 7.1 before 7.1.6
Description The issue allows local users to obtain sensitive retrieved data from arbitrary accounts in certain circumstances by leveraging previous use of a symlink during archive and retrieve actions.
Recommendations For versions 5.5 through 6.3 before 6.3.2.6, update to version 6.3.2.6 or later. For versions 6.4 before 6.4.3.3, update to version 6.4.3.3 or later. For versions 7.1 before 7.1.6, update to version 7.1.6 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-2894

Produtos afetados

Ibm Spectrum Protect