CVE-2016-2988

HIGH

IBM Tivoli Storage Manager for Virtual Environments 6.4.x-6.4.3.3 & 7.1.x-7.1.5 Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 and 7.1.x before 7.1.6 allows remote authenticated users to bypass a TSM credential requirement and obtain administrative access by leveraging multiple simultaneous logins.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21988781

Scores

CVSS v3 8.5
EPSS 0.0096
EPSS Percentile 58.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (2)
ibm/tivoli_storage_manager_for_virtual_environments 6.4
ibm/tivoli_storage_manager_for_virtual_environments 7.1
Published Nov 25, 2016
Tracked Since Feb 18, 2026