← Back

CVE-2013-3976

nvd nist
Published: Mar 26, 2014Modified: May 6, 2026

JSON object

Loading...
2.1
Vector
AV:N/AC:H/Au:S/C:P/I:N/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not properly constrain mailbox contents during certain PST restore operations, which allows remote authenticated users to read the personal e-mail of other users in opportunistic circumstances by launching an e-mail client after an administrator performs a multiple-mailbox restore.

Affected (7)

4 products
Data Protection
Flashcopy Manager
Tivoli Storage Flashcopy Manager
Tivoli Storage Manager For Mail
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 6.1
Version 6.3
Ibm
Version 2.1
Version 2.2
Version 3.1
All versions
All versions

Related CWEs

References (6)

Source: psirt@us.ibm.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.