Vulnerability Bulletins

IBM Security Bulletin: The GPFS pattern provided with IBM PureApplication System is affected by security vulnerabilities. (CVE-2016-2985 and CVE-2016-2984)

   
Affected software IBM
 
A security vulnerability has been identified in all levels of IBM Spectrum Scale and IBM GPFS that could allow a local attacker to execute commands as root. IBM PureApplication System provides a GPFS pattern and addressed the applicable CVEs.CVE(s): CVE-2016-2985, CVE-2016-2984Affected product(s) and affected version(s):· IBM PureApplication System V2.0 and V2.0.0.1(GPFS Pattern type 1.2.0.0, 1.2.0.1, and 1.2.0.2) using IBM GPFS V3.5.0.19 · IBM PureApplication System V2.1.0.1

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-the-gpfs-pattern-provided-with-ibm-pureapplication-system-is-affected-by-security-vulnerabilities-cve-2016-2985-and-cve-2016-2984/