PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-6034 IBM CVE debrief

CVE-2016-6034 is a credential-disclosure issue in IBM Tivoli Storage Manager for Virtual Environments (Data Protection for VMware). According to the NVD record, a user with high privileges could be exposed to Windows domain credentials. IBM’s advisory is listed as the vendor reference for patch guidance.

Vendor
IBM
Product
Tivoli Storage Manager For Virtual Environments Data Protection For Vmware
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-01
Original CVE updated
2026-05-13
Advisory published
2017-02-01
Advisory updated
2026-05-13

Who should care

IBM Tivoli Storage Manager for Virtual Environments / Data Protection for VMware administrators, especially teams that manage privileged access, backup infrastructure, and Windows domain credentials.

Technical summary

NVD classifies this as CVSS 3.0 AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N with CWE-200. The affected CPEs in the supplied record include IBM Tivoli Storage Manager for Virtual Environments Data Protection for VMware versions 7.1.3, 7.1.4, 7.1.4.0, 7.1.6, 7.1.6.2, and 7.1.6.3. The issue is described as potential disclosure of Windows domain credentials to a user with a high level of privileges.

Defensive priority

Medium

Recommended defensive actions

  • Check whether any deployed IBM Tivoli Storage Manager for Virtual Environments / Data Protection for VMware instances match the affected CPE versions listed in the NVD record.
  • Apply IBM’s vendor patch or remediation guidance referenced in the IBM advisory linked from NVD.
  • Review privileged-access controls around the product, since exploitation requires a user with high privileges.
  • Audit where Windows domain credentials are stored or exposed by the backup environment and confirm they are not accessible to unauthorized privileged users.
  • Use the NVD record and IBM advisory as the authoritative source for remediation status and version-specific guidance.

Evidence notes

All facts in this debrief are taken from the supplied NVD metadata and its referenced IBM vendor advisory link. The supplied record identifies the weakness as CWE-200 and provides the CVSS 3.0 vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N. The record also lists the affected IBM VMware-related versions and the IBM support document as the patch/vendor reference.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-6034 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-6034

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-6034 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6034

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.