Boletines de Vulnerabilidades

IBM Security Bulletin: Password Disclosure via FlashCopy Manager on Windows, Data Protection for Exchange, and Data Protection for SQL CVE-2015-4949


Información sobre el sistema

   
Software afectado IBM

Descripción

The password associated with Tivoli Storage Manager or the Microsoft SQL DB user is displayed in plain text via application pop-up messages for failed operations and in application trace output. CVE(s): CVE-2015-4949 Affected product(s) and affected version(s): In the context of pop-up error messages: - Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 7.1 - Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 7.1 - Tivoli Storage

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_password_disclosure_via_flashcopy_manager_on_windows_data_protection_for_exchange_and_data_protection_for_sql_cve_2015_4949?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2015-4949 ,CVE-2015-4950 ,CVE-2015-4000 ,CVE-2015-1793 ,CVE-2014-8176 ,CVE-2015-1788 ,CVE-2015-1789 ,CVE-2015-1790 ,CVE-2015-1791 and CVE-2015-1792.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-08-12

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT