PT-2016-4161 · Open+3 · Unix+5

Published

2016-08-08

·

Updated

2017-09-01

·

CVE-2016-0361

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM General Parallel File System (GPFS) versions 3.5 before 3.5.0.29 efix 6 IBM General Parallel File System (GPFS) versions 4.1.1 before 4.1.1.4 efix 9
Description The issue allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX, and Windows.
Recommendations For IBM General Parallel File System (GPFS) versions 3.5 before 3.5.0.29 efix 6, update to version 3.5.0.29 efix 6 or later. For IBM General Parallel File System (GPFS) versions 4.1.1 before 4.1.1.4 efix 9, update to version 4.1.1.4 efix 9 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-0361

Affected Products

Db2
Ibm General Parallel File System
Linux
Spectrum Scale Gui
Unix
Windows