CVE-2016-2894

low

Description

IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 before 7.1.6 allows local users to obtain sensitive retrieved data from arbitrary accounts in opportunistic circumstances by leveraging previous use of a symlink during archive and retrieve actions.

References

http://www.securitytracker.com/id/1036220

http://www.securityfocus.com/bid/91534

http://www-01.ibm.com/support/docview.wss?uid=swg21985579

http://www-01.ibm.com/support/docview.wss?uid=swg1IT13686

Details

Source: Mitre, NVD

Published: 2016-07-03

Updated: 2017-09-01

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 2.5

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Low