CVE-2014-4817
The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attackers to bypass intended access restrictions and replace file backups by using a certain backup option in conjunction with a filename…
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attackers to bypass intended access restrictions and replace file backups by using a certain backup option in conjunction with a filename that matches a previously used filename.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/tivoli storage manager
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT04884Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686874Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95444
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT04884Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686874Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95444
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.