Vulnerability Name: | CVE-2013-6335 (CCN-89054) | ||||||||
Assigned: | 2013-10-31 | ||||||||
Published: | 2014-08-12 | ||||||||
Updated: | 2020-10-29 | ||||||||
Summary: | The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N) 2.5 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-281 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-6335 Source: SECUNIA Type: Third Party Advisory 60482 Source: AIXAPAR Type: Broken Link IC96095 Source: CCN Type: IBM Security Bulletin 1680453 TSM client metadata local unauthorized access (CVE-2013-6335) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21680453 Source: CCN Type: BID-69372 IBM Tivoli Storage Manager CVE-2013-6335 Local Unauthorized Access Vulnerability Source: XF Type: UNKNOWN ibm-tsm-cve20136335-info-disc(89054) Source: XF Type: VDB Entry, Vendor Advisory ibm-tsm-cve20136335-info-disc(89054) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |