First published: Thu Feb 21 2013(Updated: )
The traditional scheduler in the client in IBM Tivoli Storage Manager (TSM) before 6.2.5.0, 6.3 before 6.3.1.0, and 6.4 before 6.4.0.1, when Prompted mode is enabled, allows remote attackers to cause a denial of service (scheduling outage) via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager | <=6.2.4.4 | |
IBM Tivoli Storage Manager | =3.1.0 | |
IBM Tivoli Storage Manager | =3.2.1 | |
IBM Tivoli Storage Manager | =4.2 | |
IBM Tivoli Storage Manager | =4.2.1 | |
IBM Tivoli Storage Manager | =4.2.2 | |
IBM Tivoli Storage Manager | =4.2.3 | |
IBM Tivoli Storage Manager | =4.2.4 | |
IBM Tivoli Storage Manager | =5.1.0 | |
IBM Tivoli Storage Manager | =5.1.1 | |
IBM Tivoli Storage Manager | =5.1.5 | |
IBM Tivoli Storage Manager | =5.1.6 | |
IBM Tivoli Storage Manager | =5.1.7 | |
IBM Tivoli Storage Manager | =5.1.8 | |
IBM Tivoli Storage Manager | =5.1.9 | |
IBM Tivoli Storage Manager | =5.1.10 | |
IBM Tivoli Storage Manager | =5.2 | |
IBM Tivoli Storage Manager | =5.2.0 | |
IBM Tivoli Storage Manager | =5.2.1 | |
IBM Tivoli Storage Manager | =5.2.2 | |
IBM Tivoli Storage Manager | =5.2.4 | |
IBM Tivoli Storage Manager | =5.2.5.1 | |
IBM Tivoli Storage Manager | =5.2.5.2 | |
IBM Tivoli Storage Manager | =5.2.5.3 | |
IBM Tivoli Storage Manager | =5.2.7 | |
IBM Tivoli Storage Manager | =5.2.8 | |
IBM Tivoli Storage Manager | =5.2.9 | |
IBM Tivoli Storage Manager | =5.3 | |
IBM Tivoli Storage Manager | =5.3.0 | |
IBM Tivoli Storage Manager | =5.3.1 | |
IBM Tivoli Storage Manager | =5.3.2 | |
IBM Tivoli Storage Manager | =5.3.2.4 | |
IBM Tivoli Storage Manager | =5.3.3 | |
IBM Tivoli Storage Manager | =5.3.4 | |
IBM Tivoli Storage Manager | =5.3.5.1 | |
IBM Tivoli Storage Manager | =5.3.6.1 | |
IBM Tivoli Storage Manager | =5.3.6.2 | |
IBM Tivoli Storage Manager | =5.3.6.3 | |
IBM Tivoli Storage Manager | =5.3.6.4 | |
IBM Tivoli Storage Manager | =5.3.6.5 | |
IBM Tivoli Storage Manager | =5.3.6.6 | |
IBM Tivoli Storage Manager | =5.4 | |
IBM Tivoli Storage Manager | =5.4.0 | |
IBM Tivoli Storage Manager | =5.4.1 | |
IBM Tivoli Storage Manager | =5.4.2 | |
IBM Tivoli Storage Manager | =5.4.2.2 | |
IBM Tivoli Storage Manager | =5.4.2.3 | |
IBM Tivoli Storage Manager | =5.4.2.4 | |
IBM Tivoli Storage Manager | =5.4.3.0 | |
IBM Tivoli Storage Manager | =5.4.3.2 | |
IBM Tivoli Storage Manager | =5.4.3.3 | |
IBM Tivoli Storage Manager | =5.4.4.0 | |
IBM Tivoli Storage Manager | =5.5.0 | |
IBM Tivoli Storage Manager | =5.5.1 | |
IBM Tivoli Storage Manager | =5.5.2 | |
IBM Tivoli Storage Manager | =6.0 | |
IBM Tivoli Storage Manager | =6.1.0 | |
IBM Tivoli Storage Manager | =6.1.1 | |
IBM Tivoli Storage Manager | =6.1.2 | |
IBM Tivoli Storage Manager | =6.1.3 | |
IBM Tivoli Storage Manager | =6.2.0 | |
IBM Tivoli Storage Manager | =6.2.0.0 | |
IBM Tivoli Storage Manager | =6.2.1 | |
IBM Tivoli Storage Manager | =6.3.0.0 | |
IBM Tivoli Storage Manager | =6.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0471 has a medium severity level as it can cause denial of service in IBM Tivoli Storage Manager.
To fix CVE-2013-0471, upgrade IBM Tivoli Storage Manager to version 6.2.5.0 or later, 6.3.1.0 or later, or 6.4.0.1 or later.
CVE-2013-0471 affects all versions of IBM Tivoli Storage Manager prior to 6.2.5.0, 6.3 before 6.3.1.0, and 6.4 before 6.4.0.1.
CVE-2013-0471 allows remote attackers to cause a scheduling outage, leading to denial of service.
Yes, CVE-2013-0471 can be exploited remotely when Promoted mode is enabled in IBM Tivoli Storage Manager.