Vulnerability Bulletins

IBM Security Bulletin: Confidential data exposure when restoring Microsoft Exchange mailboxes which have the same alias defined CVE-2015-4950

   
Affected software IBM
 
In environments with duplicated mailbox aliases, FlashCopy Manager for Microsoft Exchange, Data Protection for Microsoft Exchange, and FastBack for Microsoft Exchange may open and restore the wrong mailbox. CVE(s): CVE-2015-4950 Affected product(s) and affected version(s): Tivoli Storage FlashCopy Manager for Microsoft Exchange Server 2.1, 2.2, 3.1, 3.2, and 4.1 Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1, 6.3, 6.4, and 7.1 Tivoli Storage Manager

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_confidential_data_exposure_when_restoring_microsoft_exchange_mailboxes_which_have_the_same_alias_defined_cve_2015_4950?lang=en_us