CVE-2016-5946: IBM Spectrum Control

Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.

Affected products

  • IBM Spectrum Control: version 5.2.8 only; version 5.2.9 only; version 5.2.10 only; version 5.2.10.1 only
  • IBM Tivoli Storage Productivity Center: version 5.2.0 only; version 5.2.1 only; version 5.2.1.1 only; version 5.2.2 only; version 5.2.3 only; version 5.2.4 only; …

Published 2016-09-26. Last modified 2026-06-17.