First published: Sun Jul 17 2011(Updated: )
Buffer overflow in the Alternate Data Stream (aka ADS or named stream) functionality in the backup-archive client in IBM Tivoli Storage Manager (TSM) before 5.4.3.4, 5.5.x before 5.5.3, 6.x before 6.1.4, and 6.2.x before 6.2.2 on Windows allows local users to gain privileges via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager | <=5.4.3.3 | |
IBM Tivoli Storage Manager | =4.2 | |
IBM Tivoli Storage Manager | =4.2.1 | |
IBM Tivoli Storage Manager | =5.1.8 | |
IBM Tivoli Storage Manager | =5.2.5.1 | |
IBM Tivoli Storage Manager | =5.2.7 | |
IBM Tivoli Storage Manager | =5.2.8 | |
IBM Tivoli Storage Manager | =5.2.9 | |
IBM Tivoli Storage Manager | =5.3.0 | |
IBM Tivoli Storage Manager | =5.3.1 | |
IBM Tivoli Storage Manager | =5.3.2 | |
IBM Tivoli Storage Manager | =5.3.3 | |
IBM Tivoli Storage Manager | =5.3.6.1 | |
IBM Tivoli Storage Manager | =5.3.6.2 | |
IBM Tivoli Storage Manager | =5.3.6.3 | |
IBM Tivoli Storage Manager | =5.3.6.4 | |
IBM Tivoli Storage Manager | =5.3.6.5 | |
IBM Tivoli Storage Manager | =5.3.6.6 | |
IBM Tivoli Storage Manager | =5.4.1 | |
IBM Tivoli Storage Manager | =5.4.2 | |
IBM Tivoli Storage Manager | =5.4.3.0 | |
IBM Tivoli Storage Manager | =5.4.3.2 | |
IBM Tivoli Storage Manager | =5.5.0 | |
IBM Tivoli Storage Manager | =5.5.1 | |
IBM Tivoli Storage Manager | =5.5.2 | |
IBM Tivoli Storage Manager | =6.0 | |
IBM Tivoli Storage Manager | =6.1.0 | |
IBM Tivoli Storage Manager | =6.1.1 | |
IBM Tivoli Storage Manager | =6.1.2 | |
IBM Tivoli Storage Manager | =6.1.3 | |
IBM Tivoli Storage Manager | =6.2.0 | |
IBM Tivoli Storage Manager | =6.2.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1223 is considered a moderate severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2011-1223, you should upgrade IBM Tivoli Storage Manager to version 5.4.3.4 or later, or the versions listed in the official IBM patches.
CVE-2011-1223 affects IBM Tivoli Storage Manager versions prior to 5.4.3.4, 5.5.x before 5.5.3, and 6.x before 6.1.4.
No, CVE-2011-1223 can only be exploited by local users, as it requires local access to the affected system.
Exploiting CVE-2011-1223 may allow local users to gain elevated privileges, potentially leading to unauthorized access and control over the system.