First published: Mon May 26 2014(Updated: )
The FlashCopy Manager for VMware component in IBM Tivoli Storage FlashCopy Manager 3.1 through 4.1.0.1 does not properly check authorization for backup and restore operations, which allows local users to obtain sensitive VM data or cause a denial of service (data overwrite or disk consumption) via unspecified GUI actions.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM FlashCopy Manager | =3.1.0 | |
IBM FlashCopy Manager | =3.1.1 | |
IBM FlashCopy Manager | =3.2.0 | |
IBM FlashCopy Manager | =3.2.1 | |
IBM FlashCopy Manager | =4.1.0 | |
IBM FlashCopy Manager | =4.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6714 has a moderate severity level due to its potential to expose sensitive VM data and cause denial of service.
To fix CVE-2013-6714, ensure that you upgrade to a patched version of IBM Tivoli Storage FlashCopy Manager beyond 4.1.0.1.
CVE-2013-6714 affects IBM Tivoli Storage FlashCopy Manager versions 3.1.0 through 4.1.0.1.
An attacker can exploit CVE-2013-6714 to access sensitive VM data and may lead to data overwriting or disk consumption.
Yes, CVE-2013-6714 involves improper authorization checks for backup and restore operations, making it vulnerable.