← Vulnerability feed

Vulnerability record · CVE-2016-8940 · published 7 March 2017

CVE-2016-8940: Ibm tivoli storage manager information exposure vulnerability

Ibm · Tivoli Storage Manager

IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific database tables may allow access to passwords or other sensitive information for the product. IBM Reference #: 1998946.

8.8 CVSS 3.0 High EPSS 0.94% · top 40.5% CWE-200 · Information exposure
8.8CVSS 3.0 base score, v2 4.0
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific database tables may allow access to passwords or other sensitive information for the product. IBM Reference #: 1998946.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8940 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-3854Ibm tivoli storage manager memory buffer overflow vulnerabilityBuffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7 and 5.4 before 5.4.2 allows …EPSS 5.8%10.0CVE-2009-1178Ibm tivoli storage manager vulnerabilityUnspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vecto…EPSS 2.0%10.0CVE-2008-4563Ibm tivoli storage manager memory buffer overflow vulnerabilityHeap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Exp…EPSS 29%10.0CVE-2006-5855Ibm tivoli storage manager vulnerabilityMultiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service…EPSS 27%9.8CVE-2016-8937Ibm tivoli storage manager improper authentication vulnerabilityThe IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclo…EPSS 1.9%9.3CVE-2009-3853Ibm tivoli storage manager memory buffer overflow vulnerabilityStack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 b…EPSS 37%9.3CVE-2009-3855Ibm tivoli storage manager vulnerabilityMultiple unspecified vulnerabilities in the (1) UNIX and (2) Linux backup-archive clients, and the (3) OS/400 API client, in IBM Tivoli Storage Manag…EPSS 1.7%8.8CVE-2016-6045Ibm tivoli storage manager cross-site request forgery vulnerabilityIBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2016-8940), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.