CVE-2016-2894: IBM Tivoli Storage Manager

Low severity, CVSS 2.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 before 7.1.6 allows local users to obtain sensitive retrieved data from arbitrary accounts in opportunistic circumstances by leveraging previous use of a symlink during archive and retrieve actions.

Affected products

  • IBM Tivoli Storage Manager: version 5.5 only; version 5.5.0 only; version 5.5.2 only; version 5.5.3 only; version 5.5.4 only; version 5.5.4.1 only; …

Published 2016-07-03. Last modified 2026-06-17.