PatchSiren cyber security CVE debrief
CVE-2016-6034 IBM CVE debrief
CVE-2016-6034 is a credential-disclosure issue in IBM Tivoli Storage Manager for Virtual Environments (Data Protection for VMware). According to the NVD record, a user with high privileges could be exposed to Windows domain credentials. IBM’s advisory is listed as the vendor reference for patch guidance.
- Vendor
- IBM
- Product
- Tivoli Storage Manager For Virtual Environments Data Protection For Vmware
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-01
- Advisory updated
- 2026-05-13
Who should care
IBM Tivoli Storage Manager for Virtual Environments / Data Protection for VMware administrators, especially teams that manage privileged access, backup infrastructure, and Windows domain credentials.
Technical summary
NVD classifies this as CVSS 3.0 AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N with CWE-200. The affected CPEs in the supplied record include IBM Tivoli Storage Manager for Virtual Environments Data Protection for VMware versions 7.1.3, 7.1.4, 7.1.4.0, 7.1.6, 7.1.6.2, and 7.1.6.3. The issue is described as potential disclosure of Windows domain credentials to a user with a high level of privileges.
Defensive priority
Medium
Recommended defensive actions
- Check whether any deployed IBM Tivoli Storage Manager for Virtual Environments / Data Protection for VMware instances match the affected CPE versions listed in the NVD record.
- Apply IBM’s vendor patch or remediation guidance referenced in the IBM advisory linked from NVD.
- Review privileged-access controls around the product, since exploitation requires a user with high privileges.
- Audit where Windows domain credentials are stored or exposed by the backup environment and confirm they are not accessible to unauthorized privileged users.
- Use the NVD record and IBM advisory as the authoritative source for remediation status and version-specific guidance.
Evidence notes
All facts in this debrief are taken from the supplied NVD metadata and its referenced IBM vendor advisory link. The supplied record identifies the weakness as CWE-200 and provides the CVSS 3.0 vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N. The record also lists the affected IBM VMware-related versions and the IBM support document as the patch/vendor reference.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6034 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6034
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6034 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6034
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.