CVE Vulnerabilities

CVE-2015-7408

Published: Feb 15, 2016 | Modified: Apr 12, 2025
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.

Affected Software

NameVendorStart VersionEnd Version
Tivoli_storage_managerIbm5.5.0.0 (including)5.5.0.0 (including)
Tivoli_storage_managerIbm6.1.0.0 (including)6.1.0.0 (including)
Tivoli_storage_managerIbm6.2.0.0 (including)6.2.0.0 (including)
Tivoli_storage_managerIbm6.3.3.0 (including)6.3.3.0 (including)
Tivoli_storage_managerIbm6.3.4.0 (including)6.3.4.0 (including)
Tivoli_storage_managerIbm6.3.5.0 (including)6.3.5.0 (including)
Tivoli_storage_managerIbm7.1.0.0 (including)7.1.0.0 (including)
Tivoli_storage_managerIbm7.1.0.1 (including)7.1.0.1 (including)
Tivoli_storage_managerIbm7.1.0.2 (including)7.1.0.2 (including)
Tivoli_storage_managerIbm7.1.0.3 (including)7.1.0.3 (including)

References