CVE-2016-5946
26.09.2016, 04:59
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | spectrum_control | 5.2.8 |
ibm | spectrum_control | 5.2.9 |
ibm | spectrum_control | 5.2.10 |
ibm | spectrum_control | 5.2.10.1 |
ibm | tivoli_storage_productivity_center | 5.2.0 |
ibm | tivoli_storage_productivity_center | 5.2.1 |
ibm | tivoli_storage_productivity_center | 5.2.1.1 |
ibm | tivoli_storage_productivity_center | 5.2.2 |
ibm | tivoli_storage_productivity_center | 5.2.3 |
ibm | tivoli_storage_productivity_center | 5.2.4 |
ibm | tivoli_storage_productivity_center | 5.2.4.1 |
ibm | tivoli_storage_productivity_center | 5.2.5 |
ibm | tivoli_storage_productivity_center | 5.2.5.1 |
ibm | tivoli_storage_productivity_center | 5.2.6 |
ibm | tivoli_storage_productivity_center | 5.2.7 |
ibm | tivoli_storage_productivity_center | 5.2.7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References