8.4
CVE-2016-0392
- EPSS 0.06%
- Veröffentlicht 19.06.2016 20:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Elastic Storage Server Version2.5.0
Ibm ≫ Elastic Storage Server Version2.5.1
Ibm ≫ Elastic Storage Server Version2.5.2
Ibm ≫ Elastic Storage Server Version2.5.3
Ibm ≫ Elastic Storage Server Version2.5.4
Ibm ≫ Elastic Storage Server Version2.5.5
Ibm ≫ Elastic Storage Server Version3.0.0
Ibm ≫ Elastic Storage Server Version3.0.1
Ibm ≫ Elastic Storage Server Version3.0.2
Ibm ≫ Elastic Storage Server Version3.0.3
Ibm ≫ Elastic Storage Server Version3.0.4
Ibm ≫ Elastic Storage Server Version3.0.5
Ibm ≫ Elastic Storage Server Version3.5.0
Ibm ≫ Elastic Storage Server Version3.5.1
Ibm ≫ Elastic Storage Server Version3.5.2
Ibm ≫ Elastic Storage Server Version3.5.3
Ibm ≫ Elastic Storage Server Version3.5.4
Ibm ≫ Elastic Storage Server Version4.0.0
Ibm ≫ Elastic Storage Server Version4.0.1
Ibm ≫ Elastic Storage Server Version4.0.2
Ibm ≫ General Parallel File System Storage Server Version2.0.0
Ibm ≫ General Parallel File System Storage Server Version2.0.1
Ibm ≫ General Parallel File System Storage Server Version2.0.2
Ibm ≫ General Parallel File System Storage Server Version2.0.3
Ibm ≫ General Parallel File System Storage Server Version2.0.4
Ibm ≫ General Parallel File System Storage Server Version2.0.5
Ibm ≫ General Parallel File System Storage Server Version2.0.6
Ibm ≫ General Parallel File System Storage Server Version2.0.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.181 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.4 | 2.5 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.