Lucene search

K
cve[email protected]CVE-2015-4949
HistoryAug 23, 2015 - 1:59 a.m.

CVE-2015-4949

2015-08-2301:59:02
CWE-200
web.nvd.nist.gov
19
ibm
tivoli storage manager
vulnerability
data protection
microsoft sql server
microsoft exchange server
security vulnerability

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.3%

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 7.1 before 7.1.2, Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 7.1 before 7.1.2, and Tivoli Storage FlashCopy Manager 4.1 before 4.1.2 place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading GUI pop-up windows, a different vulnerability than CVE-2015-6557.

Affected configurations

NVD
Node
ibmtivoli_storage_flashcopy_managerMatch4.1.0
OR
ibmtivoli_storage_flashcopy_managerMatch4.1.2
OR
ibmtivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_serverMatch7.1
OR
ibmtivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_serverMatch7.2
OR
ibmtivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_serverMatch7.1
OR
ibmtivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_serverMatch7.2

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.3%

Related for CVE-2015-4949