CVE-2016-2985

EUVD-2016-4058
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
Affected Products (NVD)
VendorProductVersion
ibmspectrum_scale
4.1.1.0
ibmspectrum_scale
4.1.1.1
ibmspectrum_scale
4.1.1.2
ibmspectrum_scale
4.1.1.3
ibmspectrum_scale
4.1.1.4
ibmspectrum_scale
4.1.1.5
ibmspectrum_scale
4.1.1.6
ibmspectrum_scale
4.1.1.7
ibmspectrum_scale
4.1.1.8
ibmspectrum_scale
4.2.0.0
ibmspectrum_scale
4.2.0.1
ibmspectrum_scale
4.2.0.2
ibmspectrum_scale
4.2.0.3
ibmgeneral_parallel_file_system
3.5.0.0
ibmgeneral_parallel_file_system
3.5.0.1
ibmgeneral_parallel_file_system
3.5.0.2
ibmgeneral_parallel_file_system
3.5.0.3
ibmgeneral_parallel_file_system
3.5.0.4
ibmgeneral_parallel_file_system
3.5.0.5
ibmgeneral_parallel_file_system
3.5.0.6
ibmgeneral_parallel_file_system
3.5.0.7
ibmgeneral_parallel_file_system
3.5.0.8
ibmgeneral_parallel_file_system
3.5.0.9
ibmgeneral_parallel_file_system
3.5.0.10
ibmgeneral_parallel_file_system
3.5.0.11
ibmgeneral_parallel_file_system
3.5.0.12
ibmgeneral_parallel_file_system
3.5.0.13
ibmgeneral_parallel_file_system
3.5.0.14
ibmgeneral_parallel_file_system
3.5.0.15
ibmgeneral_parallel_file_system
3.5.0.16
ibmgeneral_parallel_file_system
3.5.0.17
ibmgeneral_parallel_file_system
3.5.0.18
ibmgeneral_parallel_file_system
3.5.0.19
ibmgeneral_parallel_file_system
3.5.0.20
ibmgeneral_parallel_file_system
3.5.0.21
ibmgeneral_parallel_file_system
3.5.0.22
ibmgeneral_parallel_file_system
3.5.0.23
ibmgeneral_parallel_file_system
3.5.0.24
ibmgeneral_parallel_file_system
3.5.0.25
ibmgeneral_parallel_file_system
3.5.0.26
ibmgeneral_parallel_file_system
3.5.0.27
ibmgeneral_parallel_file_system
3.5.0.28
ibmgeneral_parallel_file_system
3.5.0.29
ibmgeneral_parallel_file_system
3.5.0.30
ibmgeneral_parallel_file_system
3.5.0.31
ibmgeneral_parallel_file_system
4.1.0.0
ibmgeneral_parallel_file_system
4.1.0.1
ibmgeneral_parallel_file_system
4.1.0.2
ibmgeneral_parallel_file_system
4.1.0.3
ibmgeneral_parallel_file_system
4.1.0.4
ibmgeneral_parallel_file_system
4.1.0.5
ibmgeneral_parallel_file_system
4.1.0.6
ibmgeneral_parallel_file_system
4.1.0.7
ibmgeneral_parallel_file_system
4.1.0.8
𝑥
= Vulnerable software versions
Common Weakness Enumeration