CVE Vulnerabilities

CVE-2018-1550

Improper Privilege Management

Published: Sep 26, 2018 | Modified: Oct 09, 2019
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Tivoli_storage_manager Ibm 7.1.8.0 (including) 7.1.8.2 (including)
Tivoli_storage_manager Ibm 8.1.2 (including) 8.1.4 (including)
Tivoli_storage_manager_for_space_management Ibm * *
Tivoli_storage_manager_for_space_management Ibm 7.1.8.0 (including) 7.1.8.2 (including)
Tivoli_storage_manager_for_space_management Ibm 8.1.2.0 (including) 8.1.4.1 (including)
Tivoli_storage_manager_for_virtual_environments Ibm 7.1.8.0 (including) 7.1.8.2 (including)
Tivoli_storage_manager_for_virtual_environments Ibm 8.1.2.0 (including) 8.1.4.1 (including)

Potential Mitigations

References