CVE Vulnerabilities

CVE-2015-7408

Published: Feb 15, 2016 | Modified: Mar 10, 2016
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.

Affected Software

Name Vendor Start Version End Version
Tivoli_storage_manager Ibm 5.5.0.0 (including) 5.5.0.0 (including)
Tivoli_storage_manager Ibm 6.1.0.0 (including) 6.1.0.0 (including)
Tivoli_storage_manager Ibm 6.2.0.0 (including) 6.2.0.0 (including)
Tivoli_storage_manager Ibm 6.3.3.0 (including) 6.3.3.0 (including)
Tivoli_storage_manager Ibm 6.3.4.0 (including) 6.3.4.0 (including)
Tivoli_storage_manager Ibm 6.3.5.0 (including) 6.3.5.0 (including)
Tivoli_storage_manager Ibm 7.1.0.0 (including) 7.1.0.0 (including)
Tivoli_storage_manager Ibm 7.1.0.1 (including) 7.1.0.1 (including)
Tivoli_storage_manager Ibm 7.1.0.2 (including) 7.1.0.2 (including)
Tivoli_storage_manager Ibm 7.1.0.3 (including) 7.1.0.3 (including)

References