First published: Tue Mar 31 2009(Updated: )
The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager | =5.1.6 | |
IBM Tivoli Storage Manager | =5.2.0 | |
IBM Tivoli Storage Manager | =5.1.9 | |
IBM Tivoli Storage Manager | =5.1.10 | |
IBM Tivoli Storage Manager | =5.1.8 | |
IBM Tivoli Storage Manager | =5.1.0 | |
IBM Tivoli Storage Manager | =5.1.1 | |
IBM Tivoli Storage Manager | =5.1.5 | |
IBM Tivoli Storage Manager | =6.0 | |
IBM Tivoli Storage Manager | =5.1.7 | |
IBM Tivoli Storage Manager | =5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1570 is considered a medium severity vulnerability due to the potential unauthorized access to server operations.
To fix CVE-2003-1570, update IBM Tivoli Storage Manager to version 5.2.1.2 or later or apply relevant security patches.
CVE-2003-1570 affects IBM Tivoli Storage Manager versions 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1.
CVE-2003-1570 enables remote authenticated administrators to observe server console operations without proper credentials.
Mitigation without an update may be challenging, but limiting access to the server console can help reduce exposure to CVE-2003-1570.