CVE-2016-5927
IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted…
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted password by reading application-trace output.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/tivoli storage manager for space management
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT15203Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21989006Patch, Vendor Advisory
- http://www.securityfocus.com/bid/92723
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT15203Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21989006Patch, Vendor Advisory
- http://www.securityfocus.com/bid/92723
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.