Lucene search

K
kasperskyKaspersky LabKLA10210
HistoryMay 05, 2009 - 12:00 a.m.

KLA10210 Vulnerability in IBM Tivoli Storage Manager

2009-05-0500:00:00
Kaspersky Lab
threats.kaspersky.com
18

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:C/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.003

Percentile

70.9%

An unspecified vulnerability was found in IBM Tivoli Storage Manager. By exploiting this vulnerability malicious users can conduct a man-in-the-middle attack and read arbitrary files. This vulnerability can be exploited remotely at a point related to SSL.

Original advisories

Related products

IBM-Tivoli-Storage-Manager-Client

CVE list

CVE-2009-1522 high

Solution

Update to latest version

Impacts

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • RLF

Read Local Files. Exploitation of vulnerabilities with this impact can lead to reading some inaccessible files. Files that can be read depends on conсrete program errors.

Affected Products

  • IBM Tivoli Storage Manager client versions from 5.5.0.0 to 5.5.1.17

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:C/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.003

Percentile

70.9%

Related for KLA10210