CVE-2016-5927: Infoleak
IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted password by reading application-trace output.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5927?
CVE-2016-5927 is rated as moderately severe due to the risk of local users uncovering encrypted passwords.
How do I fix CVE-2016-5927?
To mitigate CVE-2016-5927, upgrade to IBM Tivoli Storage Manager for Space Management version 6.3.2.6, 6.4.3.3, or 7.1.6 or later.
Which IBM Tivoli Storage Manager for Space Management versions are affected by CVE-2016-5927?
CVE-2016-5927 affects IBM Tivoli Storage Manager for Space Management versions 6.3.0 to 6.3.2.5, 6.4.0 to 6.4.3.2, and 7.1.0 to 7.1.5.
Can local users exploit CVE-2016-5927?
Yes, local users can exploit CVE-2016-5927 by reading application-trace output to uncover an encrypted password.
Is there a workaround for CVE-2016-5927?
While upgrading is the most effective solution, limiting access to application-trace output may provide a temporary workaround for CVE-2016-5927.