First published: Wed Dec 29 2010(Updated: )
Unspecified vulnerability in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.3, 6.1.x before 6.1.4, and 6.2.x before 6.2.2 on Unix and Linux allows local users to overwrite arbitrary files via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager | =5.3.0 | |
IBM Tivoli Storage Manager | =5.3.1 | |
IBM Tivoli Storage Manager | =5.3.2 | |
IBM Tivoli Storage Manager | =5.3.2.4 | |
IBM Tivoli Storage Manager | =5.3.3 | |
IBM Tivoli Storage Manager | =5.3.4 | |
IBM Tivoli Storage Manager | =5.3.5.1 | |
IBM Tivoli Storage Manager | =5.3.6.1 | |
IBM Tivoli Storage Manager | =5.3.6.2 | |
IBM Tivoli Storage Manager | =5.3.6.3 | |
IBM Tivoli Storage Manager | =5.3.6.4 | |
IBM Tivoli Storage Manager | =5.3.6.5 | |
IBM Tivoli Storage Manager | =5.3.6.6 | |
Linux Kernel | ||
IBM Tivoli Storage Manager | =5.4.0 | |
IBM Tivoli Storage Manager | =5.4.1 | |
IBM Tivoli Storage Manager | =5.4.2 | |
IBM Tivoli Storage Manager | =5.4.2.2 | |
IBM Tivoli Storage Manager | =5.4.2.3 | |
IBM Tivoli Storage Manager | =5.4.2.4 | |
IBM Tivoli Storage Manager | =5.5.0 | |
IBM Tivoli Storage Manager | =5.5.1 | |
IBM Tivoli Storage Manager | =5.5.2 | |
IBM Tivoli Storage Manager | =6.1.0 | |
IBM Tivoli Storage Manager | =6.1.1 | |
IBM Tivoli Storage Manager | =6.1.2 | |
IBM Tivoli Storage Manager | =6.1.3 | |
IBM Tivoli Storage Manager | =6.2.0 | |
IBM Tivoli Storage Manager | =6.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4605 has been rated as a medium severity vulnerability due to the potential for local users to overwrite arbitrary files.
To fix CVE-2010-4605, upgrade to IBM Tivoli Storage Manager versions 5.3.6.10, 5.4.3.4, 5.5.3, 6.1.4, or 6.2.2 or later.
CVE-2010-4605 affects several versions of IBM Tivoli Storage Manager including 5.3.x, 5.4.x, 5.5.x, 6.1.x, and 6.2.x prior to their respective fixed versions.
CVE-2010-4605 is a local vulnerability, meaning it cannot be exploited remotely and requires local user access.
Exploitation of CVE-2010-4605 could lead to unauthorized file overwrites, which may compromise the integrity of the data on the affected system.