CVE-2015-6557: Infoleak
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6557?
CVE-2015-6557 has been assigned a severity rating of moderate due to potential unauthorized access risks.
How do I fix CVE-2015-6557?
To fix CVE-2015-6557, upgrade to the patched versions of IBM Tivoli Storage Manager or Data Protection for SQL Server indicated in the vendor advisories.
What versions are affected by CVE-2015-6557?
CVE-2015-6557 affects multiple versions of IBM Tivoli Storage Manager for Databases and Mail prior to their respective patches.
What are the potential risks associated with CVE-2015-6557?
The risks associated with CVE-2015-6557 include unauthorized access to sensitive data managed by the affected software.
Is my system vulnerable if I am using IBM Tivoli Storage Manager?
If you are using IBM Tivoli Storage Manager versions prior to the specified security updates, your system is vulnerable to CVE-2015-6557.