Back to Database
Status published
Medium
CVE-2016-8916
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password...
Vulnerability Description
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-8916
Credits & Attribution
No credits recorded in the NVD database.
References
More from ibm
View All →CVE-2021-39070
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the...
Critical
9.8
CVE-2021-39066
IBM Financial Transaction Manager 3.2.4 does not invalidate session any...
Medium
6.3
CVE-2021-39044
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request...
Medium
4.3
CVE-2020-7239
The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based...
Medium
6.1
CVE-2020-28198
The 'id' parameter of IBM Tivoli Storage Manager Version 5...
High
7
Affected Vendor
Affected Software
tivoli storage manager
Vulnerable Versions:
0, 6.4.0.0, 6.4.1, 6.4.1.0, 6.4.2, 6.4.2.100, 6.4.2.200, 6.4.2.500, 6.4.2.600, 6.4.3, 6.4.3.1, 7.1, 7.1..5.100, 7.1.0.1, 7.1.0.2, 7.1.0.3, 7.1.1, 7.1.1.1, 7.1.1.2, 7.1.1.100, 7.1.1.200, 7.1.1.300, 7.1.3, 7.1.3.000, 7.1.3.1, 7.1.3.2, 7.1.3.100, 7.1.4, 7.1.4.1, 7.1.4.2, 7.1.5, 7.1.5.200, 7.1.6, 7.1.6.2, 7.1.6.3, 7.1.6.4
Timeline
Official Publish:
May 5th, 2017
Last Modified:
August 6th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.