CVE-2019-4072: IBM Spectrum Control

Medium severity, CVSS 6.3. EPSS: 0.8% chance of exploitation in the next 30 days.

IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the application back button users can remain logged in as the current user for a short period of time, therefore users are presented with information for Spectrum Control Application. IBM X-Force ID: 157064.

Affected products

  • IBM Spectrum Control: from 5.2.8, up to and including 5.2.17.2; from 5.3.0, up to and including 5.3.1
  • IBM Tivoli Storage Productivity Center: from 5.2.0, up to and including 5.2.7.1

Published 2019-05-09. Last modified 2026-06-17.