CVE-2016-0392
Summary
| CVE | CVE-2016-0392 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-06-19 20:59:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program. |
Risk And Classification
Primary CVSS: v3.0 8.4 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-284 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 8.4 | HIGH | CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 4.6 | AV:L/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Elastic Storage Server | 2.5.0 | All | All | All |
| Application | Ibm | Elastic Storage Server | 2.5.1 | All | All | All |
| Application | Ibm | Elastic Storage Server | 2.5.2 | All | All | All |
| Application | Ibm | Elastic Storage Server | 2.5.3 | All | All | All |
| Application | Ibm | Elastic Storage Server | 2.5.4 | All | All | All |
| Application | Ibm | Elastic Storage Server | 2.5.5 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.0.0 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.0.1 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.0.2 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.0.3 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.0.4 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.0.5 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.5.0 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.5.1 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.5.2 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.5.3 | All | All | All |
| Application | Ibm | Elastic Storage Server | 3.5.4 | All | All | All |
| Application | Ibm | Elastic Storage Server | 4.0.0 | All | All | All |
| Application | Ibm | Elastic Storage Server | 4.0.1 | All | All | All |
| Application | Ibm | Elastic Storage Server | 4.0.2 | All | All | All |
| Application | Ibm | General Parallel File System Storage Server | 2.0.0 | All | All | All |
| Application | Ibm | General Parallel File System Storage Server | 2.0.1 | All | All | All |
| Application | Ibm | General Parallel File System Storage Server | 2.0.2 | All | All | All |
| Application | Ibm | General Parallel File System Storage Server | 2.0.3 | All | All | All |
| Application | Ibm | General Parallel File System Storage Server | 2.0.4 | All | All | All |
| Application | Ibm | General Parallel File System Storage Server | 2.0.5 | All | All | All |
| Application | Ibm | General Parallel File System Storage Server | 2.0.6 | All | All | All |
| Application | Ibm | General Parallel File System Storage Server | 2.0.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: The Elastic Storage Server and the GPFS Storage Server are affected by a vulnerability in IBM Spectrum Scale (CVE-2016-0392) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IBM DB2 LUW GPFS Bugs Let Local Users Deny Service and Obtain Root Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IV84206: MISC SERVICE UPDATES | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM Spectrum Scale and GPFS CVE-2016-0392 Local Command Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM GPFS / Spectrum Scale Command Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.