Local SQL Server Password Exposure in IBM Tivoli Storage Manager and FlashCopy Manager
CVE-2016-3059

6.2MEDIUM

Summary

Local users of IBM Tivoli Storage Manager and FlashCopy Manager for Microsoft SQL Server can potentially expose sensitive information, specifically cleartext SQL Server passwords. This vulnerability arises when users access the Task List in the Microsoft Management Console (MMC) GUI, enabling them to read passwords in cleartext. The affected versions of the software include specific releases prior to the patches that address this exposure, underscoring the need for users to update their systems to mitigate this risk.

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.