CVE-2007-5022: Infoleak
Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2, when using "server-initiated prompted scheduling," allows remote attackers to read a client's data, aka IC53616.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5022?
CVE-2007-5022 is classified as a medium severity vulnerability due to the potential for remote attackers to read a client's data.
How do I fix CVE-2007-5022?
To mitigate CVE-2007-5022, upgrade the IBM Tivoli Storage Manager client to version 5.1.8.1 or later, 5.2.5.2 or later, 5.3.5.3 or later, or 5.4.1.2 or later.
What versions are affected by CVE-2007-5022?
CVE-2007-5022 affects IBM Tivoli Storage Manager clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2.
Can CVE-2007-5022 be exploited remotely?
Yes, remote attackers can exploit CVE-2007-5022 to access a client's data when using server-initiated prompted scheduling.
Is there a workaround for CVE-2007-5022?
There are no official workarounds for CVE-2007-5022; the recommended solution is to upgrade to a non-vulnerable version.