Vulnerability Bulletins

IBM Security Bulletin: SQL Server Password Disclosure via IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server and IBM Tivoli Storage FlashCopy Manager for Microsoft SQL

   
Affected software IBM
 
When using IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server or IBM Tivoli Storage FlashCopy Manager for Microsoft SQL Server, the Microsoft SQL Server’s user ID and password is presented in plain text via task completion status details available within the MMC GUI’s Task List view.CVE(s): CVE-2016-3059Affected product(s) and affected version(s):The following levels of IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-sql-server-password-disclosure-via-ibm-tivoli-storage-manager-for-databases-data-protection-for-microsoft-sql-server-and-ibm-tivoli-storage-flashcopy-manager-for-microsoft-sql/