SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-8940

As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators.

HIGH 8.8EPSS 0.94%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.94%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific database tables may allow access to passwords or other sensitive information for the product. IBM Reference #: 1998946.

CVSS 3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.94% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
ibm/tivoli storage manager
Source
psirt@us.ibm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.