CVE-2016-5918: Infoleak
IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace output if the password access option is prompt and the password is changed.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5918?
CVE-2016-5918 is rated as a medium severity vulnerability.
How do I fix CVE-2016-5918?
To fix CVE-2016-5918, upgrade to IBM Tivoli Storage Manager for Space Management version 7.1.4.2 or later.
What is the impact of CVE-2016-5918?
The impact of CVE-2016-5918 is that it exposes the encrypted Tivoli Storage Manager password in application trace output, which could lead to password disclosure.
Which software is affected by CVE-2016-5918?
CVE-2016-5918 affects IBM Tivoli Storage Manager for Space Management versions up to 7.1.4.1, as well as earlier versions down to 6.4.0.0.
Is there a workaround for CVE-2016-5918?
There are no officially documented workarounds for CVE-2016-5918, so upgrading is recommended.