PT-2014-3096 · Ibm · Ibm Tivoli Storage Manager
Published
2014-08-26
·
Updated
2020-10-29
·
CVE-2013-6335
CVSS v2.0
3.3
Low
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Storage Manager (TSM) for Space Management versions 5.x through 6.1.5.5 on Solaris and HP-UX
IBM Tivoli Storage Manager (TSM) for Space Management versions 5.x through 6.2.5.2 on Linux and AIX
IBM Tivoli Storage Manager (TSM) for Space Management versions 6.3.x through 6.3.1 on Linux and AIX
IBM Tivoli Storage Manager (TSM) for Space Management versions 6.4.x through 6.4.1 on Linux and AIX
IBM Tivoli Storage Manager (TSM) for Space Management versions 7.1.x through 7.1.0.2 on Linux and AIX
Description
The issue allows local users to bypass intended access restrictions via standard filesystem operations because file permissions are not preserved across backup and restore operations.
Recommendations
For versions 5.x through 6.1.5.5 on Solaris and HP-UX, update to version 6.1.5.6 or later.
For versions 5.x through 6.2.5.2 on Linux and AIX, update to version 6.2.5.3 or later.
For versions 6.3.x through 6.3.1 on Linux and AIX, update to version 6.3.2 or later.
For versions 6.4.x through 6.4.1 on Linux and AIX, update to version 6.4.2 or later.
For versions 7.1.x through 7.1.0.2 on Linux and AIX, update to version 7.1.0.3 or later.
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Tivoli Storage Manager