VulnerabilityModified
CVE-2016-6044
IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.
MEDIUM 4.3EPSS 0.59%
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- ibm/tivoli storage manager
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg21995754Patch, Vendor Advisory
- http://www.securityfocus.com/bid/95091Third Party Advisory, VDB Entry
- http://www.ibm.com/support/docview.wss?uid=swg21995754Patch, Vendor Advisory
- http://www.securityfocus.com/bid/95091Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.