CVE-2016-8937: IBM Tivoli Storage Manager

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to the TSM server. IBM X-Force ID: 118750.

Affected products

  • IBM Tivoli Storage Manager: version 6.1 only; version 6.1.0 only; version 6.1.1 only; version 6.1.2 only; version 6.1.3 only; version 6.1.4 only; …

Published 2017-10-05. Last modified 2026-06-17.