CVE-2016-3059
Estado: ModificadaMedia (6.2)—
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local users to discover a cleartext SQL Server password by reading the Task List in the MMC GUI.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.37%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-200
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-3059",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 6.2,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.5
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2016-08-08T01:59:15.447",
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21987333",
"tags": [
"Mitigation",
"Patch",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.securitytracker.com/id/1036488",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21987333",
"tags": [
"Mitigation",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1036488",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local users to discover a cleartext SQL Server password by reading the Task List in the MMC GUI."
},
{
"lang": "es",
"value": "IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (también conocido como IBM Spectrum Protect for Databases) 6.3 en versiones anteriores a 6.3.1.7 y 6.4 en versiones anteriores a 6.4.1.9 y Tivoli Storage FlashCopy Manager for Microsoft SQL Server (también conocido como IBM Spectrum Protect Snapshot) 3.1 en versiones anteriores a 3.1.1.7 y 3.2 en versiones anteriores a 3.2.1.9 permite a usuarios locales descubrir una contraseña en texto plano SQL Server leyendo el Task List en el MMC GUI."
}
],
"lastModified": "2026-06-17T00:44:53.513",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_sql_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A33E5812-43FF-47E8-9D16-73D5281BF2FB",
"versionEndIncluding": "3.1.1.6",
"versionStartIncluding": "3.1.0.0"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_sql_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE63FEE3-0DC9-488F-B9CA-EB8EB014AB05",
"versionEndIncluding": "3.2.1.8",
"versionStartIncluding": "3.2.0.0"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A25CCD1-E25F-499B-ABEF-18FBA5A52766",
"versionEndIncluding": "6.3.1.8",
"versionStartIncluding": "6.3.0.0"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "348F7202-46C1-493A-90CD-A08187CA00F9",
"versionEndIncluding": "6.4.1.8",
"versionStartIncluding": "6.4.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}