CVE-2016-5944
Summary
| CVE | CVE-2016-5944 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-09-26 04:59:15 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string. |
Risk And Classification
Primary CVSS: v3.0 5.4 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS: 0.001970000 probability, percentile 0.413890000 (date 2026-05-07)
Problem Types: CWE-79 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.4 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 3.5 | AV:N/AC:M/Au:S/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Spectrum Control | 5.2.10 | All | All | All |
| Application | Ibm | Spectrum Control | 5.2.10.1 | All | All | All |
| Application | Ibm | Spectrum Control | 5.2.8 | All | All | All |
| Application | Ibm | Spectrum Control | 5.2.9 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.0 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.1 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.1.1 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.2 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.3 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.4 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.4.1 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.5 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.5.1 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.6 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.7 | All | All | All |
| Application | Ibm | Tivoli Storage Productivity Center | 5.2.7.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple IBM Products CVE-2016-5944 Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM Security Bulletin: Multiple Security Vulnerabilities fixed in IBM Spectrum Control - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| IBM IT16944: SECURITY APAR FOR MULTIPLE VULERNABILITIES: CVE-2016-5943, CVE-2016-5944, CVE-2016-5945, CVE-2016-5946, CVE-2016-5947 - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.