PT-2015-5489 · Ibm · Ibm General Parallel File System

Published

2015-04-06

·

Updated

2016-08-04

·

CVE-2015-1890

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM General Parallel File System (GPFS) versions 4.1 through 4.1.0.6
Description The issue in IBM General Parallel File System (GPFS) allows remote attackers to obtain sensitive information by leveraging access to a technical-support data stream. This is because the /usr/lpp/mmfs/bin/gpfs.snap utility produces an archive that might contain cleartext keys without providing a warning to review the archive for included keys.
Recommendations For IBM General Parallel File System (GPFS) versions 4.1 through 4.1.0.6, update to version 4.1.0.7 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1890

Affected Products

Ibm General Parallel File System