CVE Vulnerabilities

CVE-2018-1550

Improper Privilege Management

Published: Sep 26, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Tivoli_storage_managerIbm7.1.8.0 (including)7.1.8.2 (including)
Tivoli_storage_managerIbm8.1.2 (including)8.1.4 (including)
Tivoli_storage_manager_for_space_managementIbm**
Tivoli_storage_manager_for_space_managementIbm7.1.8.0 (including)7.1.8.2 (including)
Tivoli_storage_manager_for_space_managementIbm8.1.2.0 (including)8.1.4.1 (including)
Tivoli_storage_manager_for_virtual_environmentsIbm7.1.8.0 (including)7.1.8.2 (including)
Tivoli_storage_manager_for_virtual_environmentsIbm8.1.2.0 (including)8.1.4.1 (including)

Potential Mitigations

References