Boletines de Vulnerabilidades

IBM Security Bulletin: IBM Tivoli Storage Manager ASNODENAME Vulnerability (CVE-2015-7408)

   
Software afectado IBM
 
Unauthorized Tivoli Storage Manager client sessions using the ASNODENAME option may run as authorized sessions allowing the user to generate or retrieve backup data for which they are not authorized. CVE(s): CVE-2015-7408Affected product(s) and affected version(s):This vulnerability affects the following IBM Tivoli Storage Manager (IBM Spectrum Protect) server levels: 7.1.0.0 through 7.1.3.x 6.3.0.0 through 6.3.5.0 6.2 all levels 6.1 all levels 5.5 all levels Refer to the following

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_tivoli_storage_manager_asnodename_vulnerability_cve_2015_7408?lang=en_us