PT-2017-9883 · Ibm · Ibm Tivoli Storage Manager

Kęstutis Gudinavičius

·

Published

2017-10-05

·

Updated

2017-10-25

·

CVE-2016-8937

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Tivoli Storage Manager versions 7.1 and 8.1
Description The default authentication protocol of the IBM Tivoli Storage Manager is susceptible to a brute force attack due to the disclosure of excessive information during the authentication process. This could allow an attacker to obtain user or administrative access to the TSM server.
Recommendations For versions 7.1 and 8.1, consider changing the default authentication protocol to a more secure alternative to mitigate the risk of brute force attacks. As a temporary workaround, restrict access to the TSM server and limit the number of authentication attempts to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8937

Affected Products

Ibm Tivoli Storage Manager