CVE-2003-1570
Summary
| CVE | CVE-2003-1570 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-03-31 18:24:44 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Tivoli Storage Manager | 5.1.0 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 5.1.1 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 5.1.10 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 5.1.5 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 5.1.6 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 5.1.7 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 5.1.8 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 5.1.9 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 5.2.0 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 5.2.1 | All | All | All |
| Application | Ibm | Tivoli Storage Manager | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM APARs Fixed in Tivoli Storage Manager Server Version 6.1 - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM Tivoli Storage Manager Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IC37554: TSM SERVER MAY ALLOW UNAUTHORIZED ACCESS TO SERVER VIA A CONSOLE MODE SESSION DUE TO SESSION EXPOSURE | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| IBM Tivoli Storage Manager Lets Local Users Monitor Server Activities - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM Tivoli Storage Manager Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.