CVE-2016-8937: Critical severity IBM Tivoli Storage Manager vulnerability
The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to the TSM server. IBM X-Force ID: 118750.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8937?
CVE-2016-8937 has a medium severity rating due to its potential for a brute force attack allowing unauthorized access.
How do I fix CVE-2016-8937?
To fix CVE-2016-8937, update IBM Tivoli Storage Manager to the latest version where the authentication protocol vulnerability has been addressed.
What versions of IBM Tivoli Storage Manager are affected by CVE-2016-8937?
CVE-2016-8937 affects IBM Tivoli Storage Manager versions 7.1 and 8.1 as well as multiple versions of 6.x and 6.4.
Can CVE-2016-8937 lead to data breaches?
Yes, CVE-2016-8937 can lead to data breaches if an attacker successfully exploits the authentication vulnerability.
What are the implications of CVE-2016-8937 for businesses?
Businesses using vulnerable versions of IBM Tivoli Storage Manager may face increased risks of unauthorized access and potential data loss.