CVE-2016-5927
Estado: ModificadaMedia (5.5)—
IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted password by reading application-trace output.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.32%
- Percentil entre todas las CVEs puntuadas: 22
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT15203
- http://www-01.ibm.com/support/docview.wss?uid=swg21989006
- http://www.securityfocus.com/bid/92723
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT15203
- http://www-01.ibm.com/support/docview.wss?uid=swg21989006
- http://www.securityfocus.com/bid/92723
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-5927",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2016-09-12T10:59:02.647",
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT15203",
"tags": [
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21989006",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.securityfocus.com/bid/92723",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT15203",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21989006",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/92723",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted password by reading application-trace output."
},
{
"lang": "es",
"value": "IBM Tivoli Storage Manager para Space Management (también conocido como Spectrum Protect para Space Management) 6.3.x en versiones anteriores a 6.3.2.6, 6.4.x en versiones anteriores a 6.4.3.3, y 7.1.x en versiones anteriores a 7.1.6, cuando está configurado cierto rastreo dsmsetpw, permite a usuarios locales descubrir una contraseña cifrada leyendo el resultado del rastreo de aplicación."
}
],
"lastModified": "2026-06-17T00:50:15.363",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D1030A8-2770-49BF-93EC-8C2FB08C3FCA"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D08D7BF-6C7C-4C53-8D75-506EE7BFA0D8"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3ED1C563-6B46-4F15-A3EE-9732A6E135CF"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.4.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58B2465F-1445-4CB2-8130-D97D4524A290"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10C95B6A-2B34-4DF9-B4D8-E1DF2986BE20"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "321D004F-094E-4FBD-9D9D-850EED24A0E3"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:6.4.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "112C19AF-1BCC-4FBD-AC2D-A8399AF4DA12"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:7.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0749732C-0F60-4D69-B933-4058C652E31E"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:7.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6BAA7180-6E41-4836-B03E-5DC0C55E0093"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:7.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A267E3D-9912-46E7-9E5C-2FFEB503CA76"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:7.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "74755D0A-28C1-4071-8DD1-FA452F8128B3"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_space_management:7.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6000AC77-53A1-4249-89BD-83B7E8E82CC6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}