First published: Mon May 26 2014(Updated: )
The Data Protection for VMware component in IBM Tivoli Storage Manager for Virtual Environments (TSMVE) 6.3 through 7.1.0.2 does not properly check authorization for backup and restore operations, which allows local users to obtain sensitive VM data or cause a denial of service (disk consumption) via unspecified GUI actions.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager for Virtual Environments | =6.3.0.0 | |
IBM Tivoli Storage Manager for Virtual Environments | =6.3.1.0 | |
IBM Tivoli Storage Manager for Virtual Environments | =6.3.2.0 | |
IBM Tivoli Storage Manager for Virtual Environments | =6.3.2.1 | |
IBM Tivoli Storage Manager for Virtual Environments | =6.3.3.0 | |
IBM Tivoli Storage Manager for Virtual Environments | =6.4.0.0 | |
IBM Tivoli Storage Manager for Virtual Environments | =6.4.1.0 | |
IBM Tivoli Storage Manager for Virtual Environments | =7.1.0.0 | |
IBM Tivoli Storage Manager for Virtual Environments | =7.1.0.1 | |
IBM Tivoli Storage Manager for Virtual Environments | =7.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6713 has a medium severity rating due to its potential to allow unauthorized access to sensitive VM data.
To mitigate CVE-2013-6713, upgrade IBM Tivoli Storage Manager for Virtual Environments to version 7.1.0.3 or later.
CVE-2013-6713 affects IBM Tivoli Storage Manager for Virtual Environments versions 6.3 through 7.1.0.2.
Yes, CVE-2013-6713 can lead to data loss by allowing unauthorized users to manipulate backup and restore operations.
There is no official temporary workaround for CVE-2013-6713; it is recommended to apply the software updates as soon as possible.