Lucene search

K
cveIbmCVE-2013-6713
HistoryMay 26, 2014 - 7:55 p.m.

CVE-2013-6713

2014-05-2619:55:04
CWE-264
ibm
web.nvd.nist.gov
20
cve-2013-6713
data protection
vmware
ibm tivoli storage manager
tsmve
authorization
backup
restore
local users
denial of service
vulnerability

CVSS2

4.1

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

5.1%

The Data Protection for VMware component in IBM Tivoli Storage Manager for Virtual Environments (TSMVE) 6.3 through 7.1.0.2 does not properly check authorization for backup and restore operations, which allows local users to obtain sensitive VM data or cause a denial of service (disk consumption) via unspecified GUI actions.

Affected configurations

Nvd
Node
ibmtivoli_storage_manager_for_virtual_environmentsMatch6.3.0.0
OR
ibmtivoli_storage_manager_for_virtual_environmentsMatch6.3.1.0
OR
ibmtivoli_storage_manager_for_virtual_environmentsMatch6.3.2.0
OR
ibmtivoli_storage_manager_for_virtual_environmentsMatch6.3.2.1
OR
ibmtivoli_storage_manager_for_virtual_environmentsMatch6.3.3.0
OR
ibmtivoli_storage_manager_for_virtual_environmentsMatch6.4.0.0
OR
ibmtivoli_storage_manager_for_virtual_environmentsMatch6.4.1.0
OR
ibmtivoli_storage_manager_for_virtual_environmentsMatch7.1.0.0
OR
ibmtivoli_storage_manager_for_virtual_environmentsMatch7.1.0.1
OR
ibmtivoli_storage_manager_for_virtual_environmentsMatch7.1.0.2
VendorProductVersionCPE
ibmtivoli_storage_manager_for_virtual_environments6.3.0.0cpe:2.3:a:ibm:tivoli_storage_manager_for_virtual_environments:6.3.0.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_virtual_environments6.3.1.0cpe:2.3:a:ibm:tivoli_storage_manager_for_virtual_environments:6.3.1.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_virtual_environments6.3.2.0cpe:2.3:a:ibm:tivoli_storage_manager_for_virtual_environments:6.3.2.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_virtual_environments6.3.2.1cpe:2.3:a:ibm:tivoli_storage_manager_for_virtual_environments:6.3.2.1:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_virtual_environments6.3.3.0cpe:2.3:a:ibm:tivoli_storage_manager_for_virtual_environments:6.3.3.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_virtual_environments6.4.0.0cpe:2.3:a:ibm:tivoli_storage_manager_for_virtual_environments:6.4.0.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_virtual_environments6.4.1.0cpe:2.3:a:ibm:tivoli_storage_manager_for_virtual_environments:6.4.1.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_virtual_environments7.1.0.0cpe:2.3:a:ibm:tivoli_storage_manager_for_virtual_environments:7.1.0.0:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_virtual_environments7.1.0.1cpe:2.3:a:ibm:tivoli_storage_manager_for_virtual_environments:7.1.0.1:*:*:*:*:*:*:*
ibmtivoli_storage_manager_for_virtual_environments7.1.0.2cpe:2.3:a:ibm:tivoli_storage_manager_for_virtual_environments:7.1.0.2:*:*:*:*:*:*:*

CVSS2

4.1

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2013-6713