PT-2017-9883 · Ibm · Ibm Tivoli Storage Manager
Kęstutis Gudinavičius
·
Publicado
2017-10-05
·
Atualizado
2017-10-25
·
CVE-2016-8937
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Storage Manager versions 7.1 and 8.1
Description
The default authentication protocol of the IBM Tivoli Storage Manager is susceptible to a brute force attack due to the disclosure of excessive information during the authentication process. This could allow an attacker to obtain user or administrative access to the TSM server.
Recommendations
For versions 7.1 and 8.1, consider changing the default authentication protocol to a more secure alternative to mitigate the risk of brute force attacks. As a temporary workaround, restrict access to the TSM server and limit the number of authentication attempts to minimize the risk of exploitation.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Tivoli Storage Manager