First published: Sun Jul 03 2016(Updated: )
IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 before 7.1.6 allows local users to obtain sensitive retrieved data from arbitrary accounts in opportunistic circumstances by leveraging previous use of a symlink during archive and retrieve actions.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager | =5.5 | |
IBM Tivoli Storage Manager | =5.5.0 | |
IBM Tivoli Storage Manager | =5.5.2 | |
IBM Tivoli Storage Manager | =5.5.3 | |
IBM Tivoli Storage Manager | =5.5.4 | |
IBM Tivoli Storage Manager | =5.5.4.1 | |
IBM Tivoli Storage Manager | =5.5.4.2 | |
IBM Tivoli Storage Manager | =5.5.4.3 | |
IBM Tivoli Storage Manager | =6.1 | |
IBM Tivoli Storage Manager | =6.1.0 | |
IBM Tivoli Storage Manager | =6.1.1 | |
IBM Tivoli Storage Manager | =6.1.2 | |
IBM Tivoli Storage Manager | =6.1.3 | |
IBM Tivoli Storage Manager | =6.1.4 | |
IBM Tivoli Storage Manager | =6.1.5 | |
IBM Tivoli Storage Manager | =6.1.5.4 | |
IBM Tivoli Storage Manager | =6.1.5.5 | |
IBM Tivoli Storage Manager | =6.1.5.6 | |
IBM Tivoli Storage Manager | =6.2 | |
IBM Tivoli Storage Manager | =6.2.0 | |
IBM Tivoli Storage Manager | =6.2.1 | |
IBM Tivoli Storage Manager | =6.2.2 | |
IBM Tivoli Storage Manager | =6.2.3 | |
IBM Tivoli Storage Manager | =6.2.4 | |
IBM Tivoli Storage Manager | =6.2.4.7 | |
IBM Tivoli Storage Manager | =6.3 | |
IBM Tivoli Storage Manager | =6.3.0 | |
IBM Tivoli Storage Manager | =6.3.0.5 | |
IBM Tivoli Storage Manager | =6.3.0.15 | |
IBM Tivoli Storage Manager | =6.3.0.17 | |
IBM Tivoli Storage Manager | =6.3.1 | |
IBM Tivoli Storage Manager | =6.3.1.2 | |
IBM Tivoli Storage Manager | =6.3.2.2 | |
IBM Tivoli Storage Manager | =6.4 | |
IBM Tivoli Storage Manager | =6.4.0 | |
IBM Tivoli Storage Manager | =6.4.0.1 | |
IBM Tivoli Storage Manager | =6.4.0.4 | |
IBM Tivoli Storage Manager | =6.4.0.5 | |
IBM Tivoli Storage Manager | =6.4.0.7 | |
IBM Tivoli Storage Manager | =6.4.1.3 | |
IBM Tivoli Storage Manager | =6.4.1.7 | |
IBM Tivoli Storage Manager | =6.4.2.1 | |
IBM Tivoli Storage Manager | =6.4.2.100 | |
IBM Tivoli Storage Manager | =6.4.2.200 | |
IBM Tivoli Storage Manager | =6.4.3 | |
IBM Tivoli Storage Manager | =6.4.3.1 | |
IBM Tivoli Storage Manager | =7.1 | |
IBM Tivoli Storage Manager | =7.1..5.100 | |
IBM Tivoli Storage Manager | =7.1.0.1 | |
IBM Tivoli Storage Manager | =7.1.0.2 | |
IBM Tivoli Storage Manager | =7.1.0.3 | |
IBM Tivoli Storage Manager | =7.1.1 | |
IBM Tivoli Storage Manager | =7.1.1.1 | |
IBM Tivoli Storage Manager | =7.1.1.100 | |
IBM Tivoli Storage Manager | =7.1.1.200 | |
IBM Tivoli Storage Manager | =7.1.1.300 | |
IBM Tivoli Storage Manager | =7.1.2 | |
IBM Tivoli Storage Manager | =7.1.3 | |
IBM Tivoli Storage Manager | =7.1.3.000 | |
IBM Tivoli Storage Manager | =7.1.3.1 | |
IBM Tivoli Storage Manager | =7.1.3.2 | |
IBM Tivoli Storage Manager | =7.1.3.100 | |
IBM Tivoli Storage Manager | =7.1.4 | |
IBM Tivoli Storage Manager | =7.1.4.1 | |
IBM Tivoli Storage Manager | =7.1.5 | |
IBM Tivoli Storage Manager | =7.1.5.200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2894 is considered to have a medium severity level.
To address CVE-2016-2894, upgrade IBM Spectrum Protect to the latest version as specified by IBM.
CVE-2016-2894 affects local users of IBM Spectrum Protect versions 5.5 to 7.1.
CVE-2016-2894 enables local users to access sensitive retrieved data from arbitrary accounts.
CVE-2016-2894 was reported in March 2016.