First published: Thu Jan 23 2014(Updated: )
The client in IBM Tivoli Storage Manager (TSM) 6.3.1 and 6.4.0 on Windows does not preserve permissions of Resilient File System (ReFS) files across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager | =6.3.1 | |
IBM Tivoli Storage Manager | =6.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5371 is considered a medium severity vulnerability due to its potential to allow local users to bypass access restrictions.
To fix CVE-2013-5371, ensure you upgrade to IBM Tivoli Storage Manager version 6.4.1 or later, which addresses this issue.
CVE-2013-5371 affects IBM Tivoli Storage Manager versions 6.3.1 and 6.4.0 on Windows.
Yes, CVE-2013-5371 can affect data integrity by allowing unauthorized access to files due to permission issues.
CVE-2013-5371 is a client-side vulnerability affecting the IBM Tivoli Storage Manager.