PT-2016-4161 · Open+3 · Unix+5
Published
2016-08-08
·
Updated
2017-09-01
·
CVE-2016-0361
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM General Parallel File System (GPFS) versions 3.5 before 3.5.0.29 efix 6
IBM General Parallel File System (GPFS) versions 4.1.1 before 4.1.1.4 efix 9
Description
The issue allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX, and Windows.
Recommendations
For IBM General Parallel File System (GPFS) versions 3.5 before 3.5.0.29 efix 6, update to version 3.5.0.29 efix 6 or later.
For IBM General Parallel File System (GPFS) versions 4.1.1 before 4.1.1.4 efix 9, update to version 4.1.1.4 efix 9 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Db2
Ibm General Parallel File System
Linux
Spectrum Scale Gui
Unix
Windows