CVE-2016-6110: Medium severity IBM Tivoli Storage Manager vulnerability
Published Feb 1, 2017
·Updated
IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user.
Affected Software
12 affected components
IBM Tivoli Storage Manager<=7.1.6.3
IBM Tivoli Storage Manager=7.1.0.0
IBM Tivoli Storage Manager For Virtual Environments Data Protection For Vmware Vmware<=7.1.6.3
IBM Tivoli Storage Manager For Virtual Environments Data Protection For Vmware Vmware=7.1.0.0
Linux Linux kernel
Microsoft Windows
All of the following
Any of the following
IBM Tivoli Storage Manager<=7.1.6.3
IBM Tivoli Storage Manager=7.1.0.0
IBM Tivoli Storage Manager For Virtual Environments Data Protection For Vmware Vmware<=7.1.6.3
IBM Tivoli Storage Manager For Virtual Environments Data Protection For Vmware Vmware=7.1.0.0
Any of the following
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Feb 1, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6110?
CVE-2016-6110 is categorized as a moderate severity vulnerability due to the exposure of unencrypted login credentials.
2
How do I fix CVE-2016-6110?
To mitigate CVE-2016-6110, users should update their IBM Tivoli Storage Manager to version 7.1.6.4 or later.
3
Who is affected by CVE-2016-6110?
CVE-2016-6110 affects IBM Tivoli Storage Manager versions up to 7.1.6.3 and version 7.1.0.0.
4
What impact does CVE-2016-6110 have?
The impact of CVE-2016-6110 allows local users to potentially access unencrypted VMware vCenter login credentials.
5
Is there a workaround for CVE-2016-6110?
A potential workaround for CVE-2016-6110 includes restricting local user access to the IBM Tivoli Storage Manager where possible.