CVE-2015-7425
The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.4 and…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 3.1 before 3.1.1.3, 3.2 before 3.2.0.6, and 4.1 before 4.1.4 allows remote attackers to obtain administrative privileges via a crafted URL that triggers back-end function execution.
- CVSS 3.0
- 10.0 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 3.92% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/tivoli storage flashcopy manager for vmware · ibm/tivoli storage manager for virtual environments data protection for vmware
- Source
- psirt@us.ibm.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.