PT-2017-9883 · Ibm · Ibm Tivoli Storage Manager
Kęstutis Gudinavičius
·
Published
2017-10-05
·
Updated
2017-10-25
·
CVE-2016-8937
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Storage Manager versions 7.1 and 8.1
Description
The default authentication protocol of the IBM Tivoli Storage Manager is susceptible to a brute force attack due to the disclosure of excessive information during the authentication process. This could allow an attacker to obtain user or administrative access to the TSM server.
Recommendations
For versions 7.1 and 8.1, consider changing the default authentication protocol to a more secure alternative to mitigate the risk of brute force attacks. As a temporary workaround, restrict access to the TSM server and limit the number of authentication attempts to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Tivoli Storage Manager