CVE-2017-1301: Medium severity ibm tivoli storage manager vulnerability
IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various files on the system, which could allow the attacker to overwrite arbitrary files on the system with elevated privileges. IBM X-Force ID: 125163.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1301?
CVE-2017-1301 has a medium severity rating due to the potential for local attackers to exploit the symlink vulnerability.
How do I fix CVE-2017-1301?
To fix CVE-2017-1301, apply the latest patches or updates provided by IBM for the affected versions of IBM Spectrum Protect.
What versions of IBM Spectrum Protect are affected by CVE-2017-1301?
CVE-2017-1301 affects IBM Spectrum Protect versions 6.1 through 8.1.
What type of attack can be executed due to CVE-2017-1301?
CVE-2017-1301 allows a local attacker to execute a symlink attack by manipulating temporary files.
Can external attackers exploit CVE-2017-1301?
CVE-2017-1301 is a local vulnerability, meaning it can only be exploited by users with local access to the system.