CVE-2003-1361
Summary
| CVE | CVE-2003-1361 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Tivoli Storage Manager | 3.1.0 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 3.2.1 | All | All | All |
| Application | Veritas | Bare Metal Restore | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| A potential security problem exists on UNIX platforms of VERITAS Bare Metal Restore for Tivoli Storage Manager. Unauthorized root access to the BMR Main Server may be obtained by anyone with network access to a BMR Main Server by forcing BMR to run arbitrary commands under the administrator account (root). | af854a3a-2127-422b-91ae-364da2661108 | seer.support.veritas.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Veritas Bare Metal Restore Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Neohapsis Archives - Bugtraq - VERITAS Software Technical Advisory (fwd) - From da_at_securityfocus.com | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| A potential security problem exists on UNIX platforms of VERITAS Bare Metal Restore for Tivoli Storage Manager. Unauthorized root access to the BMR Main Server may be obtained by anyone with network access to a BMR Main Server by forcing BMR to run arbitrary commands under the administrator account (root). | af854a3a-2127-422b-91ae-364da2661108 | seer.support.veritas.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.