Lucene search

K
cveIbmCVE-2016-0252
HistoryJul 08, 2016 - 1:59 a.m.

CVE-2016-0252

2016-07-0801:59:01
CWE-200
ibm
web.nvd.nist.gov
27
cve-2016-0252
ibm
control center
sterling
local users
decryption
master key
security vulnerability

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.1

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

32.1%

IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors.

Affected configurations

Nvd
Node
ibmcontrol_centerMatch6.0.0.0
Node
ibmsterling_control_centerMatch5.4.0.0
OR
ibmsterling_control_centerMatch5.4.0.1
OR
ibmsterling_control_centerMatch5.4.1
OR
ibmsterling_control_centerMatch5.4.1.0
OR
ibmsterling_control_centerMatch5.4.2
OR
ibmsterling_control_centerMatch5.4.2.0
VendorProductVersionCPE
ibmcontrol_center6.0.0.0cpe:2.3:a:ibm:control_center:6.0.0.0:*:*:*:*:*:*:*
ibmsterling_control_center5.4.0.0cpe:2.3:a:ibm:sterling_control_center:5.4.0.0:*:*:*:*:*:*:*
ibmsterling_control_center5.4.0.1cpe:2.3:a:ibm:sterling_control_center:5.4.0.1:*:*:*:*:*:*:*
ibmsterling_control_center5.4.1cpe:2.3:a:ibm:sterling_control_center:5.4.1:*:*:*:*:*:*:*
ibmsterling_control_center5.4.1.0cpe:2.3:a:ibm:sterling_control_center:5.4.1.0:*:*:*:*:*:*:*
ibmsterling_control_center5.4.2cpe:2.3:a:ibm:sterling_control_center:5.4.2:*:*:*:*:*:*:*
ibmsterling_control_center5.4.2.0cpe:2.3:a:ibm:sterling_control_center:5.4.2.0:*:*:*:*:*:*:*

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.1

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

32.1%

Related for CVE-2016-0252