CVE-2009-1521
Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17, and the TSM Express client 5.3.3.0 through 5.3.6.5, allows…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17, and the TSM Express client 5.3.3.0 through 5.3.6.5, allows attackers to read or modify arbitrary files via unknown vectors.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- ibm/tivoli storage manager client · ibm/tivoli storage manager express
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/32604
- http://www-01.ibm.com/support/docview.wss?uid=swg21384389Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IC59779Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1235
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50329
- http://secunia.com/advisories/32604
- http://www-01.ibm.com/support/docview.wss?uid=swg21384389Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IC59779Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1235
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50329
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.