CVE-2016-3059: Infoleak
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local users to discover a cleartext SQL Server password by reading the Task List in the MMC GUI.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3059?
CVE-2016-3059 is rated as a medium severity vulnerability.
How do I fix CVE-2016-3059?
To fix CVE-2016-3059, upgrade to the versions 6.3.1.7 or 6.4.1.9 for Tivoli Storage Manager, or 3.1.1.7 or 3.2.1.9 for Tivoli Storage FlashCopy Manager.
What products are affected by CVE-2016-3059?
CVE-2016-3059 affects IBM Tivoli Storage Manager for Databases and IBM Tivoli Storage FlashCopy Manager for Microsoft SQL Server.
What are the potential consequences of CVE-2016-3059?
Exploitation of CVE-2016-3059 may allow unauthorized access to database backups.
When was CVE-2016-3059 disclosed?
CVE-2016-3059 was disclosed in 2016.