MEDIUM · 6.3

CVE-2019-4072

IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the ap...

Vulnerability Description

IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the application back button users can remain logged in as the current user for a short period of time, therefore users are presented with information for Spectrum Control Application. IBM X-Force ID: 157064.

CVSS Score

6.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
IbmSpectrum Control>= 5.2.8, <= 5.2.17.2
IbmTivoli Storage Productivity Center>= 5.2.0, <= 5.2.7.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-4072?

CVE-2019-4072 is a vulnerability with a CVSS score of 6.3 (MEDIUM). IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the ap...

How severe is CVE-2019-4072?

CVE-2019-4072 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-4072?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Spectrum Control, Ibm Tivoli Storage Productivity Center.