CVE-2013-6335: Low severity ibm tivoli storage manager vulnerability
The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6335?
CVE-2013-6335 is considered a medium severity vulnerability due to its impact on file permission preservation.
How do I fix CVE-2013-6335?
To fix CVE-2013-6335, you should upgrade IBM Tivoli Storage Manager to versions 6.2.5.3, 6.3.2, 6.4.2, or 7.1.0.3 or later.
What systems are affected by CVE-2013-6335?
CVE-2013-6335 affects multiple versions of IBM Tivoli Storage Manager on Linux, AIX, Solaris, and HP-UX.
What is the main issue caused by CVE-2013-6335?
The main issue caused by CVE-2013-6335 is the failure to preserve file permissions during backup and archive operations.
Is CVE-2013-6335 still a risk if I’m using an updated version of Tivoli Storage Manager?
If you are using an updated version of Tivoli Storage Manager beyond the specified vulnerable versions, CVE-2013-6335 should no longer be a risk.