First published: Mon Aug 08 2016(Updated: )
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local users to discover a cleartext SQL Server password by reading the Task List in the MMC GUI.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM FlashCopy Manager | >=3.1.0.0<=3.1.1.6 | |
IBM FlashCopy Manager | >=3.2.0.0<=3.2.1.8 | |
IBM Tivoli Storage Manager for Databases Data Protection for Microsoft SQL Server | >=6.3.0.0<=6.3.1.8 | |
IBM Tivoli Storage Manager for Databases Data Protection for Microsoft SQL Server | >=6.4.0.0<=6.4.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3059 is rated as a medium severity vulnerability.
To fix CVE-2016-3059, upgrade to the versions 6.3.1.7 or 6.4.1.9 for Tivoli Storage Manager, or 3.1.1.7 or 3.2.1.9 for Tivoli Storage FlashCopy Manager.
CVE-2016-3059 affects IBM Tivoli Storage Manager for Databases and IBM Tivoli Storage FlashCopy Manager for Microsoft SQL Server.
Exploitation of CVE-2016-3059 may allow unauthorized access to database backups.
CVE-2016-3059 was disclosed in 2016.