CVE-2013-6335
3.3
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 3.4 / Impact: 4.9
Source: NVD
Description
The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
Affected (5)
Products: Ibm: Tivoli Storage Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.1 to 6.2.5.3 |
| Running on/with | Platform Versions |
|---|---|
Ibm Aix | All versions |
Linux Linux Kernel | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.1 to 6.1.5.6 |
| Running on/with | Platform Versions |
|---|---|
Hp Hp Ux | All versions |
Oracle Solaris | All versions |
References (8)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Timeline
No history available yet.