This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Ibm First view 2014-02-04
Product General Parallel File System Last view 2018-06-13
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:ibm:general_parallel_file_system:3.5:*:*:*:*:*:*:* 8
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.7:*:*:*:*:*:*:* 7
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.16:*:*:*:*:*:*:* 7
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.11:*:*:*:*:*:*:* 7
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.3:*:*:*:*:*:*:* 7
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.9:*:*:*:*:*:*:* 7
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.0:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.15:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.14:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.6:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.12:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.4:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.10:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.2:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.13:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.8:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:4.1.0.1:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:general_parallel_file_system:4.1.0.0:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:4.1.0.6:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.20:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.26:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:4.1.0.4:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:4.1.0.7:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:4.1.0.3:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.24:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.23:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:4.1:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.18:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.19:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.17:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.25:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.21:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.22:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:4.1.0.2:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:4.1.0.8:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:4.1.0.5:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:general_parallel_file_system:3.4:*:*:*:*:*:*:* 4
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.30:*:*:*:*:*:*:* 3
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.28:*:*:*:*:*:*:* 3
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.27:*:*:*:*:*:*:* 3
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.29:*:*:*:*:*:*:* 3
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.1:*:*:*:*:*:*:* 3
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.5:*:*:*:*:*:*:* 3
cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.31:*:*:*:*:*:*:* 3
cpe:2.3:a:ibm:general_parallel_file_system:3.4.0.23:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:general_parallel_file_system:3.4.0.15:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:general_parallel_file_system:3.4.0.7:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:general_parallel_file_system:3.4.0.24:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:general_parallel_file_system:3.4.0.4:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:general_parallel_file_system:3.4.0.17:*:*:*:*:*:*:* 2

Related : CVE

  Date Alert Description
7.8 2018-06-13 CVE-2018-1431

A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID: 139240.

3.3 2018-03-02 CVE-2017-1654

IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.

7.2 2017-02-01 CVE-2016-6115

IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash.

7 2016-11-24 CVE-2016-2985

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.

7 2016-11-24 CVE-2016-2984

IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted command-line parameters to a /usr/lpp/mmfs/bin/ setuid program.

6.5 2016-08-07 CVE-2016-0361

IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords.

4 2016-01-02 CVE-2015-7403

IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors.

2.1 2015-10-25 CVE-2015-4981

IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors.

7.2 2015-10-25 CVE-2015-4974

IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.

3.5 2015-04-05 CVE-2015-1890

/usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentially containing cleartext keys, and lacks a warning about reviewing this archive to detect included keys, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

4.9 2015-03-23 CVE-2015-0199

The mmfslinux kernel module in IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to cause a denial of service (memory corruption) via unspecified character-device ioctl calls.

10 2015-03-23 CVE-2015-0198

IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary programs as root via unspecified vectors.

7.2 2015-03-23 CVE-2015-0197

IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges for program execution via unspecified vectors.

4 2014-02-04 CVE-2014-0834

IBM General Parallel File System (GPFS) 3.4 through 3.4.0.27 and 3.5 through 3.5.0.16 allows attackers to cause a denial of service (daemon crash) via crafted arguments to a setuid program.

CWE : Common Weakness Enumeration

%idName
27% (3) CWE-264 Permissions, Privileges, and Access Controls
27% (3) CWE-200 Information Exposure
9% (1) CWE-399 Resource Management Errors
9% (1) CWE-287 Improper Authentication
9% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
9% (1) CWE-77 Improper Sanitization of Special Elements used in a Command ('Comma...
9% (1) CWE-20 Improper Input Validation

Information Assurance Vulnerability Management (IAVM)

id Description
2015-B-0090 Multiple Vulnerabilities in IBM DB2
Severity: Category I - VMSKEY: V0061115

Nessus® Vulnerability Scanner

id Description
2015-09-18 Name: The remote database server is affected by multiple vulnerabilities.
File: db2_105fp6.nasl - Type: ACT_GATHER_INFO
2015-07-18 Name: The remote database server is affected by multiple vulnerabilities.
File: db2_101fp5.nasl - Type: ACT_GATHER_INFO
2015-07-18 Name: The remote database server is affected by multiple vulnerabilities.
File: db2_105fp5_multi_vuln.nasl - Type: ACT_GATHER_INFO
2014-06-18 Name: The remote database server is affected by multiple vulnerabilities.
File: db2_98fp5_multi_vuln.nasl - Type: ACT_GATHER_INFO
2014-02-14 Name: A clustered file system on the remote host is affected by a denial of service...
File: ibm_gpfs_isg3t1020542_debian.nasl - Type: ACT_GATHER_INFO
2014-02-14 Name: A clustered file system on the remote host is affected by a denial of service...
File: ibm_gpfs_isg3t1020542_rhel.nasl - Type: ACT_GATHER_INFO
2014-02-14 Name: A clustered file system on the remote host is affected by a denial of service...
File: ibm_gpfs_isg3t1020542_sles.nasl - Type: ACT_GATHER_INFO
2014-02-14 Name: A clustered file system on the remote host is affected by a denial of service...
File: ibm_gpfs_isg3t1020542_windows.nasl - Type: ACT_GATHER_INFO