CVE-2016-3059: IBM Tivoli Storage Flashcopy Manager For SQL Server
Medium severity, CVSS 6.2. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local users to discover a cleartext SQL Server password by reading the Task List in the MMC GUI.
Affected products
- IBM Tivoli Storage Flashcopy Manager For SQL Server: from 3.1.0.0, up to and including 3.1.1.6; from 3.2.0.0, up to and including 3.2.1.8
- IBM Tivoli Storage Manager For Databases Data Protection For Microsoft SQL Server: from 6.3.0.0, up to and including 6.3.1.8; from 6.4.0.0, up to and including 6.4.1.8
Published 2016-08-08. Last modified 2026-06-17.