CVE-2016-8916

Severity
5.5MEDIUM
EPSS
0.1%
top 83.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 5
Latest updateMay 17

Description

IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-828p-6fw9-6vw8: IBM Tivoli Storage Manager 52022-05-17
CVEList
CVE-2016-8916: IBM Tivoli Storage Manager 52017-05-05
OSV
libarchive vulnerabilities2016-07-14

💬Community

1
Bugzilla
CVE-2015-8916 libarchive: NULL pointer access in RAR parser through bsdtar2016-06-21
CVE-2016-8916 (MEDIUM CVSS 5.5) | IBM Tivoli Storage Manager 5.5 | cvebase.io