CVE-2016-5946
26.09.2016, 04:59
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_control | 5.2.8 |
| ibm | spectrum_control | 5.2.9 |
| ibm | spectrum_control | 5.2.10 |
| ibm | spectrum_control | 5.2.10.1 |
| ibm | tivoli_storage_productivity_center | 5.2.0 |
| ibm | tivoli_storage_productivity_center | 5.2.1 |
| ibm | tivoli_storage_productivity_center | 5.2.1.1 |
| ibm | tivoli_storage_productivity_center | 5.2.2 |
| ibm | tivoli_storage_productivity_center | 5.2.3 |
| ibm | tivoli_storage_productivity_center | 5.2.4 |
| ibm | tivoli_storage_productivity_center | 5.2.4.1 |
| ibm | tivoli_storage_productivity_center | 5.2.5 |
| ibm | tivoli_storage_productivity_center | 5.2.5.1 |
| ibm | tivoli_storage_productivity_center | 5.2.6 |
| ibm | tivoli_storage_productivity_center | 5.2.7 |
| ibm | tivoli_storage_productivity_center | 5.2.7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References