CVE-2016-5944: IBM Spectrum Control

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.

Affected products

  • IBM Spectrum Control: version 5.2.8 only; version 5.2.9 only; version 5.2.10 only; version 5.2.10.1 only
  • IBM Tivoli Storage Productivity Center: version 5.2.0 only; version 5.2.1 only; version 5.2.1.1 only; version 5.2.2 only; version 5.2.3 only; version 5.2.4 only; …

Published 2016-09-26. Last modified 2026-06-17.