CVE-2016-8939: Infoleak
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8939?
CVE-2016-8939 has a medium severity rating as it exposes sensitive password information stored in the Windows Registry.
How do I fix CVE-2016-8939?
To fix CVE-2016-8939, update your IBM Tivoli Storage Manager to the latest version where the vulnerability is patched.
Which versions of IBM Tivoli Storage Manager are affected by CVE-2016-8939?
IBM Tivoli Storage Manager versions 6.1, 7.1, and 8.1 are affected by CVE-2016-8939.
What impact does CVE-2016-8939 have on my system?
The impact of CVE-2016-8939 can result in unauthorized access to sensitive password information stored in the Windows Registry.
Is CVE-2016-8939 a remote or local attack vulnerability?
CVE-2016-8939 can be exploited through local access, as it involves access to the Windows Registry where passwords are stored.