CVE-2013-5371
The client in IBM Tivoli Storage Manager (TSM) 6.3.1 and 6.4.0 on Windows does not preserve permissions of Resilient File System (ReFS) files across backup and restore operations, which allows local users to bypass intended access restrictions via…
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
The client in IBM Tivoli Storage Manager (TSM) 6.3.1 and 6.4.0 on Windows does not preserve permissions of Resilient File System (ReFS) files across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/tivoli storage manager
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC92933Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21662608Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86661
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC92933Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21662608Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86661
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.