First published: Fri Sep 21 2007(Updated: )
Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2, when using "server-initiated prompted scheduling," allows remote attackers to read a client's data, aka IC53616.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager Client | >=5.1<5.1.8.1 | |
IBM Tivoli Storage Manager Client | >=5.2<5.2.5.2 | |
IBM Tivoli Storage Manager Client | >=5.3<5.3.5.3 | |
IBM Tivoli Storage Manager Client | >=5.4<5.4.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5022 is classified as a medium severity vulnerability due to the potential for remote attackers to read a client's data.
To mitigate CVE-2007-5022, upgrade the IBM Tivoli Storage Manager client to version 5.1.8.1 or later, 5.2.5.2 or later, 5.3.5.3 or later, or 5.4.1.2 or later.
CVE-2007-5022 affects IBM Tivoli Storage Manager clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2.
Yes, remote attackers can exploit CVE-2007-5022 to access a client's data when using server-initiated prompted scheduling.
There are no official workarounds for CVE-2007-5022; the recommended solution is to upgrade to a non-vulnerable version.