CVE-2014-6195
1.9
Vector
AV:L/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 3.4 / Impact: 2.9
Source: NVD
Description
The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 before 5.5.4.4 on AIX, Linux, and Solaris; 5.4.x and 5.5.x on Windows and z/OS; 6.1 before 6.1.5.7 on z/OS; 6.1 and 6.2 before 6.2.5.2 on Windows, before 6.2.5.3 on AIX and Linux x86, and before 6.2.5.4 on Linux Z and Solaris; 6.3 before 6.3.2.1 on AIX, before 6.3.2.2 on Windows, and before 6.3.2.3 on Linux; 6.4 before 6.4.2.1; and 7.1 before 7.1.1 in IBM TSM for Mail, when the Data Protection for Lotus Domino component is used, allow local users to bypass authentication and restore a Domino database or transaction-log backup via unspecified vectors.
Affected (7)
Products: Ibm: Tivoli Storage Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.5 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.4 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.1 |
| Running on/with | Platform Versions |
|---|---|
Ibm Linux On Ibm Z | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.4 |
| Running on/with | Platform Versions |
|---|---|
Ibm Z/os | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.3 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2 |
| Running on/with | Platform Versions |
|---|---|
Ibm Aix | All versions |
Ibm Linux On Ibm Z | All versions |
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
Oracle Solaris | All versions |
References (6)
Source: psirt@us.ibm.com
PatchVendor Advisory
Source: psirt@us.ibm.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.