CVE-2016-5934
Status: ModifiedHigh (7.3)—
IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted DLL in the victim's path, an attacker could exploit this vulnerability when the installer is executed to run arbitrary code on the system with privileges of the victim.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Base score: 7.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.03%
- Percentile among all scored CVEs: 63
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-264
References
Raw JSON (NVD)
Show
{
"id": "CVE-2016-5934",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.3,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.3
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "IBM Corporation",
"product": "Tivoli Storage Manager FastBack",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"status": "affected",
"version": "6.1"
},
{
"status": "affected",
"version": "5.5.0"
},
{
"status": "affected",
"version": "5.5.1"
},
{
"status": "affected",
"version": "5.5.2"
},
{
"status": "affected",
"version": "5.5.2.0"
},
{
"status": "affected",
"version": "5.5.3.0"
},
{
"status": "affected",
"version": "5.5.4.0"
},
{
"status": "affected",
"version": "5.5.5.0"
},
{
"status": "affected",
"version": "5.5.6.0"
},
{
"status": "affected",
"version": "6.1.0.0"
},
{
"status": "affected",
"version": "6.1.0.1"
},
{
"status": "affected",
"version": "3.5.604"
},
{
"status": "affected",
"version": "3.5.705"
},
{
"status": "affected",
"version": "3.5.801"
},
{
"status": "affected",
"version": "3.5.802"
},
{
"status": "affected",
"version": "3.5.804"
},
{
"status": "affected",
"version": "5.5.7"
},
{
"status": "affected",
"version": "6.1.1.0"
},
{
"status": "affected",
"version": "unspecified"
},
{
"status": "affected",
"version": "6.1.1"
},
{
"status": "affected",
"version": "6.1.2"
},
{
"status": "affected",
"version": "6.1.3"
},
{
"status": "affected",
"version": "6.1.4"
},
{
"status": "affected",
"version": "6.1.5"
},
{
"status": "affected",
"version": "6.1.6"
},
{
"status": "affected",
"version": "6.1.7"
},
{
"status": "affected",
"version": "6.1.8"
},
{
"status": "affected",
"version": "6.1.9"
},
{
"status": "affected",
"version": "6.1.10"
},
{
"status": "affected",
"version": "6.1.11"
},
{
"status": "affected",
"version": "6.1.12"
},
{
"status": "affected",
"version": "5.5.6"
}
]
}
]
}
],
"published": "2017-02-08T22:59:00.637",
"references": [
{
"url": "http://www.ibm.com/support/docview.wss?uid=swg21988908",
"tags": [
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.securityfocus.com/bid/92614",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.ibm.com/support/docview.wss?uid=swg21988908",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/92614",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted DLL in the victim's path, an attacker could exploit this vulnerability when the installer is executed to run arbitrary code on the system with privileges of the victim."
},
{
"lang": "es",
"value": "El instalador IBM Tivoli Storage Manager FastBack podría permitir a un atacante remoto ejecutar código arbitrario en el sistema. Al colocar una DLL especialmente manipulada en el camino de la víctima, un atacante podría explotar esta vulnerabilidad cuando el instalador se ejecuta para ejecutar código arbitrario en el sistema con privilegios de la víctima."
}
],
"lastModified": "2026-06-17T00:50:15.700",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:*:*:*:*:demo:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B30ED7B4-7A0B-4461-A0F4-478D8721512F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}