IBM Tivoli Storage Manager HSM for Windows Password Exposure Vulnerability
CVE-2016-5918

4.7MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
8 February 2017

Summary

A vulnerability exists within IBM Tivoli Storage Manager HSM for Windows, where the encrypted password for Tivoli Storage Manager can be revealed in application trace logs. This occurs when the password access option is set to prompt, and the password is subsequently changed. Such exposure can lead to potential unauthorized access to sensitive data, thereby compromising data integrity and security.

Affected Version(s)

Tivoli Storage Manager HSM for Windows 5.3.2.0

Tivoli Storage Manager HSM for Windows 5.3.5.0

Tivoli Storage Manager HSM for Windows 5.4.0.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.