CVE-2018-1550: Medium severity ibm tivoli storage manager vulnerability
Published Sep 26, 2018
·Updated
IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696.
Affected Software
7 affected components
IBM Tivoli Storage Manager>=7.1.8.0<=7.1.8.2
IBM Tivoli Storage Manager>=8.1.2<=8.1.4
IBM Tivoli Storage Manager for Space Management
IBM Tivoli Storage Manager for Space Management>=7.1.8.0<=7.1.8.2
IBM Tivoli Storage Manager for Space Management>=8.1.2.0<=8.1.4.1
Ibm Tivoli Storage Manager For Virtual Environments>=7.1.8.0<=7.1.8.2
Ibm Tivoli Storage Manager For Virtual Environments>=8.1.2.0<=8.1.4.1
Remediation
Patch Available
Event History
Sep 26, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-1550.
2
What is the severity of CVE-2018-1550?
The severity of CVE-2018-1550 is medium (CVSS score 5.5).
3
How can a local user exploit CVE-2018-1550?
A local user can exploit CVE-2018-1550 to corrupt or delete highly sensitive information, causing a denial of service to other users.
4
Which versions of IBM Spectrum Protect are affected by CVE-2018-1550?
IBM Spectrum Protect versions 7.1 to 7.1.8.2 and 8.1.2 to 8.1.4 are affected by CVE-2018-1550.
5
How can I fix the vulnerability CVE-2018-1550?
To fix the vulnerability CVE-2018-1550, update IBM Spectrum Protect to a version that is not affected by the vulnerability.