Local SQL Server Password Exposure in IBM Tivoli Storage Manager and FlashCopy Manager
CVE-2016-3059
6.2MEDIUM
Key Information:
- Vendor
- IBM
- Status
- Vendor
- CVE Published:
- 8 August 2016
Summary
Local users of IBM Tivoli Storage Manager and FlashCopy Manager for Microsoft SQL Server can potentially expose sensitive information, specifically cleartext SQL Server passwords. This vulnerability arises when users access the Task List in the Microsoft Management Console (MMC) GUI, enabling them to read passwords in cleartext. The affected versions of the software include specific releases prior to the patches that address this exposure, underscoring the need for users to update their systems to mitigate this risk.
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved