Lucene search

K
cveIbmCVE-2016-5927
HistorySep 12, 2016 - 10:59 a.m.

CVE-2016-5927

2016-09-1210:59:02
CWE-200
ibm
web.nvd.nist.gov
30
ibm
tivoli
storage manager
spectrum protect
space management
cve-2016-5927
nvd
security
password leakage

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

5.1%

IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted password by reading application-trace output.

Affected configurations

Nvd
Node
ibmtivoli_storage_manager_for_space_managementMatch6.3.0
OR
ibmtivoli_storage_manager_for_space_managementMatch6.3.2
OR
ibmtivoli_storage_manager_for_space_managementMatch6.4.0
OR
ibmtivoli_storage_manager_for_space_managementMatch6.4.0.0
OR
ibmtivoli_storage_manager_for_space_managementMatch6.4.1
OR
ibmtivoli_storage_manager_for_space_managementMatch6.4.2
OR
ibmtivoli_storage_manager_for_space_managementMatch6.4.3
OR
ibmtivoli_storage_manager_for_space_managementMatch7.1.0
OR
ibmtivoli_storage_manager_for_space_managementMatch7.1.1
OR
ibmtivoli_storage_manager_for_space_managementMatch7.1.2
OR
ibmtivoli_storage_manager_for_space_managementMatch7.1.3
OR
ibmtivoli_storage_manager_for_space_managementMatch7.1.4
VendorProductVersionCPE
ibmtivoli_storage_manager_for_space_management6.3.0cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.3.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_space_management6.3.2cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.3.2:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_space_management6.4.0cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.4.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_space_management6.4.0.0cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.4.0.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_space_management6.4.1cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.4.1:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_space_management6.4.2cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.4.2:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_space_management6.4.3cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.4.3:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_space_management7.1.0cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:7.1.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_space_management7.1.1cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:7.1.1:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_space_management7.1.2cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:7.1.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2016-5927