HIGH · 7.0

CVE-2016-6043

Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.

Vulnerability Description

Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.

CVSS Score

7.0

HIGH

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IbmTivoli Storage Manager6.4.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-6043?

CVE-2016-6043 is a vulnerability with a CVSS score of 7.0 (HIGH). Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.

How severe is CVE-2016-6043?

CVE-2016-6043 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-6043?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Tivoli Storage Manager.