Vulnerability Bulletins

IBM Security Bulletin: IBM Tivoli Storage Manager ASNODENAME Vulnerability (CVE-2015-7408)

   
Affected software IBM
 
Unauthorized Tivoli Storage Manager client sessions using the ASNODENAME option may run as authorized sessions allowing the user to generate or retrieve backup data for which they are not authorized. CVE(s): CVE-2015-7408Affected product(s) and affected version(s):This vulnerability affects the following IBM Tivoli Storage Manager (IBM Spectrum Protect) server levels: 7.1.0.0 through 7.1.3.x 6.3.0.0 through 6.3.5.0 6.2 all levels 6.1 all levels 5.5 all levels Refer to the following

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_tivoli_storage_manager_asnodename_vulnerability_cve_2015_7408?lang=en_us