First published: Wed Feb 08 2017(Updated: )
IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace output if the password access option is prompt and the password is changed.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager for Space Management | <=7.1.4.1 | |
IBM Tivoli Storage Manager for Space Management | =7.1.0.0 | |
Microsoft Windows | ||
IBM Tivoli Storage Manager for Space Management | <=6.4.3.0 | |
IBM Tivoli Storage Manager for Space Management | =6.4.0.0 | |
IBM Tivoli Storage Manager for Space Management | <=6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5918 is rated as a medium severity vulnerability.
To fix CVE-2016-5918, upgrade to IBM Tivoli Storage Manager for Space Management version 7.1.4.2 or later.
The impact of CVE-2016-5918 is that it exposes the encrypted Tivoli Storage Manager password in application trace output, which could lead to password disclosure.
CVE-2016-5918 affects IBM Tivoli Storage Manager for Space Management versions up to 7.1.4.1, as well as earlier versions down to 6.4.0.0.
There are no officially documented workarounds for CVE-2016-5918, so upgrading is recommended.