Lucene search

K
cveIbmCVE-2013-6335
HistoryAug 26, 2014 - 10:55 a.m.

CVE-2013-6335

2014-08-2610:55:04
CWE-281
ibm
web.nvd.nist.gov
26
ibm tivoli storage manager
backup-archive client
file permissions
access restrictions
nvd
security vulnerability
cve-2013-6335

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.

Affected configurations

Nvd
Node
ibmtivoli_storage_managerRange5.16.2.5.3
OR
ibmtivoli_storage_managerRange6.3.06.3.2
OR
ibmtivoli_storage_managerRange6.4.06.4.2
OR
ibmtivoli_storage_managerRange7.1.0.07.1.0.3
AND
ibmaixMatch-
OR
linuxlinux_kernelMatch-
Node
ibmtivoli_storage_managerRange5.16.1.5.6
AND
hphp-uxMatch-
OR
oraclesolarisMatch--
VendorProductVersionCPE
ibmtivoli_storage_manager*cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*
ibmaix-cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
hphp-ux-cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
oraclesolaris-cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:-:*

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2013-6335