First published: Tue Nov 18 2014(Updated: )
The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attackers to bypass intended access restrictions and replace file backups by using a certain backup option in conjunction with a filename that matches a previously used filename.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager | =5.1.0 | |
IBM Tivoli Storage Manager | =5.1.1 | |
IBM Tivoli Storage Manager | =5.1.5 | |
IBM Tivoli Storage Manager | =5.1.6 | |
IBM Tivoli Storage Manager | =5.1.7 | |
IBM Tivoli Storage Manager | =5.1.8 | |
IBM Tivoli Storage Manager | =5.1.9 | |
IBM Tivoli Storage Manager | =5.1.10 | |
IBM Tivoli Storage Manager | =5.2 | |
IBM Tivoli Storage Manager | =5.2.0 | |
IBM Tivoli Storage Manager | =5.2.1 | |
IBM Tivoli Storage Manager | =5.2.2 | |
IBM Tivoli Storage Manager | =5.2.4 | |
IBM Tivoli Storage Manager | =5.2.5.1 | |
IBM Tivoli Storage Manager | =5.2.5.2 | |
IBM Tivoli Storage Manager | =5.2.5.3 | |
IBM Tivoli Storage Manager | =5.2.7 | |
IBM Tivoli Storage Manager | =5.2.8 | |
IBM Tivoli Storage Manager | =5.2.9 | |
IBM Tivoli Storage Manager | =5.3 | |
IBM Tivoli Storage Manager | =5.3.0 | |
IBM Tivoli Storage Manager | =5.3.1 | |
IBM Tivoli Storage Manager | =5.3.2 | |
IBM Tivoli Storage Manager | =5.3.2.4 | |
IBM Tivoli Storage Manager | =5.3.3 | |
IBM Tivoli Storage Manager | =5.3.4 | |
IBM Tivoli Storage Manager | =5.3.5.1 | |
IBM Tivoli Storage Manager | =5.3.6.1 | |
IBM Tivoli Storage Manager | =5.3.6.2 | |
IBM Tivoli Storage Manager | =5.3.6.3 | |
IBM Tivoli Storage Manager | =5.3.6.4 | |
IBM Tivoli Storage Manager | =5.3.6.5 | |
IBM Tivoli Storage Manager | =5.3.6.6 | |
IBM Tivoli Storage Manager | =5.4 | |
IBM Tivoli Storage Manager | =5.4.0 | |
IBM Tivoli Storage Manager | =5.4.1 | |
IBM Tivoli Storage Manager | =5.4.2 | |
IBM Tivoli Storage Manager | =5.4.2.2 | |
IBM Tivoli Storage Manager | =5.4.2.3 | |
IBM Tivoli Storage Manager | =5.4.2.4 | |
IBM Tivoli Storage Manager | =5.4.3.0 | |
IBM Tivoli Storage Manager | =5.4.3.2 | |
IBM Tivoli Storage Manager | =5.4.3.3 | |
IBM Tivoli Storage Manager | =5.4.4.0 | |
IBM Tivoli Storage Manager | =5.5.0 | |
IBM Tivoli Storage Manager | =5.5.1 | |
IBM Tivoli Storage Manager | =5.5.2 | |
IBM Tivoli Storage Manager | =5.5.3 | |
IBM Tivoli Storage Manager | =5.5.4 | |
IBM Tivoli Storage Manager | =5.5.4.1 | |
IBM Tivoli Storage Manager | =6.0 | |
IBM Tivoli Storage Manager | =6.1.0 | |
IBM Tivoli Storage Manager | =6.1.1 | |
IBM Tivoli Storage Manager | =6.1.2 | |
IBM Tivoli Storage Manager | =6.1.3 | |
IBM Tivoli Storage Manager | =6.1.4 | |
IBM Tivoli Storage Manager | =6.1.5 | |
IBM Tivoli Storage Manager | =6.1.5.4 | |
IBM Tivoli Storage Manager | =6.2.0 | |
IBM Tivoli Storage Manager | =6.2.0.0 | |
IBM Tivoli Storage Manager | =6.2.1 | |
IBM Tivoli Storage Manager | =6.2.2 | |
IBM Tivoli Storage Manager | =6.2.3 | |
IBM Tivoli Storage Manager | =6.2.4 | |
IBM Tivoli Storage Manager | =6.2.4.4 | |
IBM Tivoli Storage Manager | =6.2.4.7 | |
IBM Tivoli Storage Manager | =6.2.6 | |
IBM Tivoli Storage Manager | =6.2.7 | |
IBM Tivoli Storage Manager | =6.3.0 | |
IBM Tivoli Storage Manager | =6.3.0.0 | |
IBM Tivoli Storage Manager | =6.3.0.1 | |
IBM Tivoli Storage Manager | =6.3.0.17 | |
IBM Tivoli Storage Manager | =6.3.1 | |
IBM Tivoli Storage Manager | =6.3.2 | |
IBM Tivoli Storage Manager | =6.3.2.1 | |
IBM Tivoli Storage Manager | =6.3.3 | |
IBM Tivoli Storage Manager | =6.3.4 | |
IBM Tivoli Storage Manager | =6.3.5 | |
IBM Tivoli Storage Manager | =6.3.5.1 | |
IBM Tivoli Storage Manager | =6.4.0 | |
IBM Tivoli Storage Manager | =6.4.0.0 | |
IBM Tivoli Storage Manager | =6.4.1 | |
IBM Tivoli Storage Manager | =6.4.2 | |
IBM Tivoli Storage Manager | =7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4817 is classified as a medium severity vulnerability due to its potential to allow unauthorized file replacement.
To fix CVE-2014-4817, upgrade IBM Tivoli Storage Manager to version 6.3.5.10 or later, or 7.1.1.100 or later.
CVE-2014-4817 can allow remote attackers to bypass access restrictions and overwrite existing file backups.
CVE-2014-4817 affects IBM Tivoli Storage Manager versions 5.x, 6.x prior to 6.3.5.10, and 7.x prior to 7.1.1.100.
There is no specific workaround for CVE-2014-4817 other than applying the recommended updates to fix the vulnerability.