CVE-2016-2988: High severity ibm tivoli storage manager for virtual environments vulnerability
IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 and 7.1.x before 7.1.6 allows remote authenticated users to bypass a TSM credential requirement and obtain administrative access by leveraging multiple simultaneous logins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2988?
CVE-2016-2988 has been assigned a medium severity level due to the potential for unauthorized administrative access.
How do I fix CVE-2016-2988?
To fix CVE-2016-2988, upgrade IBM Tivoli Storage Manager for Virtual Environments to version 6.4.3.4 or 7.1.6 or later.
Who is affected by CVE-2016-2988?
CVE-2016-2988 affects users of IBM Tivoli Storage Manager for Virtual Environments versions 6.4.x before 6.4.3.4 and 7.1.x before 7.1.6.
What is the nature of the vulnerability in CVE-2016-2988?
The vulnerability allows remote authenticated users to bypass a credential requirement and gain administrative access.
Are there any workarounds for CVE-2016-2988?
There are no official workarounds provided for CVE-2016-2988, so updating to a patched version is recommended.