CVE-2016-5943
https://notcve.org/view.php?id=CVE-2016-5943
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properties, via unspecified vectors. IBM Spectrum Control (anteriormente Tivoli Storage Productivity Center) 5.2.x en versiones anteriores a 5.2.11 permite a usuarios remotos autenticados eludir restricciones destinadas al acceso y leer detalles de tarea o editar propiedades, a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT16944 http://www-01.ibm.com/support/docview.wss?uid=swg21988625 http://www.securityfocus.com/bid/93084 • CWE-284: Improper Access Control •
CVE-2016-5946
https://notcve.org/view.php?id=CVE-2016-5946
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL. Vulnerabilidad de salto de directorio en IBM Spectrum Control (anteriormente Tivoli Storage Productivity Center) 5.2.x en versiones anteriores a 5.2.11 permite a usuarios remotos autenticados leer archivos arbitrarios a través de un .. (punto punto) en una URL. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT16944 http://www-01.ibm.com/support/docview.wss?uid=swg21988625 http://www.securityfocus.com/bid/93086 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •