CVE-2014-6185: High severity ibm tivoli storage manager vulnerability
dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict shared-library loading, which allows local users to gain privileges via a crafted DSO file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6185?
CVE-2014-6185 is considered to have a moderate severity level as it allows local users to gain elevated privileges.
How do I fix CVE-2014-6185?
To fix CVE-2014-6185, upgrade to IBM Tivoli Storage Manager versions 6.3.2.3, 6.4.2.2, or 7.1.1.3 or later.
Which versions of IBM Tivoli Storage Manager are affected by CVE-2014-6185?
CVE-2014-6185 affects IBM Tivoli Storage Manager versions 6.3 prior to 6.3.2.3, 6.4 prior to 6.4.2.2, and 7.1 prior to 7.1.1.3.
Who can exploit CVE-2014-6185?
CVE-2014-6185 can be exploited by local users who have the capability to run crafted DSO files.
What is the impact of CVE-2014-6185?
The impact of CVE-2014-6185 allows an attacker to execute arbitrary code with elevated privileges.