CVE-2015-4927: High severity ibm tivoli storage manager vulnerability
The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions for unspecified files, which allows local users to gain privileges by writing to a file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4927?
CVE-2015-4927 is classified as a moderate severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2015-4927?
To fix CVE-2015-4927, update IBM Tivoli Storage Manager to version 6.3.6 or 7.1.3 or later.
What systems are affected by CVE-2015-4927?
CVE-2015-4927 affects IBM Tivoli Storage Manager versions 6.3.3 to 6.3.5.1 and 7.1 to 7.1.2 on Linux and AIX.
What type of vulnerability is CVE-2015-4927?
CVE-2015-4927 is a local privilege escalation vulnerability caused by world-writable file permissions.
Who can exploit CVE-2015-4927?
Any local user on a vulnerable system can exploit CVE-2015-4927 to gain elevated privileges.