First published: Sat Jan 02 2016(Updated: )
The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware | =7.1 | |
IBM Spectrum Protect Snapshot | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-7426 is classified as high due to its potential impact on data confidentiality and integrity.
To fix CVE-2015-7426, upgrade to IBM Spectrum Protect for Virtual Environments 7.1.3.0 or later and Tivoli Storage FlashCopy Manager for VMware 4.1.3.0 or later.
CVE-2015-7426 affects IBM Spectrum Protect for Virtual Environments 7.1 (versions before 7.1.3.0) and Tivoli Storage FlashCopy Manager for VMware 4.1 (versions before 4.1.3.0).
Yes, CVE-2015-7426 can be exploited remotely if a vulnerability in the IBM GUI is leveraged.
Failing to address CVE-2015-7426 may lead to unauthorized access to sensitive data and possible data loss.