The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/34498 - Vendor Advisory | |
References | () http://securitytracker.com/id?1021947 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21375360 - | |
References | () http://www-1.ibm.com/support/docview.wss?uid=swg1IC37554 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/34285 - | |
References | () http://www.vupen.com/english/advisories/2009/0881 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/49536 - |
Information
Published : 2009-03-31 18:24
Updated : 2024-11-20 23:47
NVD link : CVE-2003-1570
Mitre link : CVE-2003-1570
CVE.ORG link : CVE-2003-1570
JSON object : View
Products Affected
ibm
- tivoli_storage_manager
CWE
CWE-287
Improper Authentication