CVE-2013-6335
The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does…
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
- CVSS 2.0
- 3.3 LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-281
- Affected
- ibm/tivoli storage manager
- Source
- psirt@us.ibm.com
References
- http://secunia.com/advisories/60482Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC96095Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21680453Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89054VDB Entry, Vendor Advisory
- http://secunia.com/advisories/60482Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC96095Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21680453Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89054VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.