IBM Tivoli Storage Manager 6.3.6.100

CPE Details

IBM Tivoli Storage Manager 6.3.6.100
6.3.6.100
2017-06-14
16h47 +00:00
2021-06-08
15h10 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ibm:tivoli_storage_manager:6.3.6.100:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

tivoli_storage_manager

Version

6.3.6.100

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2016-8937 2017-10-05 17h00 +00:00 The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to the TSM server. IBM X-Force ID: 118750.
9.8
Critical
CVE-2017-1301 2017-10-05 17h00 +00:00 IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various files on the system, which could allow the attacker to overwrite arbitrary files on the system with elevated privileges. IBM X-Force ID: 125163.
5.5
Medium
CVE-2017-1339 2017-10-05 17h00 +00:00 IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum protect client or administrator password which can result in information disclosure or a denial of service. IBM X-Force ID: 126247.
4.4
Medium
CVE-2017-1378 2017-10-05 17h00 +00:00 IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.
7.8
High
CVE-2016-8939 2017-06-07 15h00 +00:00 IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.
5.5
Medium
CVE-2016-6110 2017-02-01 21h00 +00:00 IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user.
6.5
Medium
CVE-2016-5985 2017-02-01 19h00 +00:00 The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer and execute arbitrary code on the system or cause a system crash.
7.8
High