{"api_version":"1","generated_at":"2026-07-23T10:15:33+00:00","cve":"CVE-2003-1361","urls":{"html":"https://cve.report/CVE-2003-1361","api":"https://cve.report/api/cve/CVE-2003-1361.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1361","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1361"},"summary":{"title":"CVE-2003-1361","description":"Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://seer.support.veritas.com/docs/254442.htm","name":"http://seer.support.veritas.com/docs/254442.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"A potential security problem exists on UNIX platforms of VERITAS Bare Metal Restore for Tivoli Storage Manager. Unauthorized root access to the BMR Main Server may be obtained by anyone with network access to a BMR Main Server by forcing BMR to run arbitrary commands under the administrator account (root).","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11418","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11418","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6928","name":"http://www.securityfocus.com/bid/6928","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Veritas Bare Metal Restore Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2003-02/0333.html","name":"http://archives.neohapsis.com/archives/bugtraq/2003-02/0333.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Neohapsis Archives - Bugtraq - VERITAS Software Technical Advisory (fwd) - From da_at_securityfocus.com","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://seer.support.veritas.com/docs/252933.htm","name":"http://seer.support.veritas.com/docs/252933.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"A potential security problem exists on UNIX platforms of VERITAS Bare Metal Restore for Tivoli Storage Manager. Unauthorized root access to the BMR Main Server may be obtained by anyone with network access to a BMR Main Server by forcing BMR to run arbitrary commands under the administrator account (root).","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1361","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1361","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1361","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager","cpe6":"3.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1361","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager","cpe6":"3.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1361","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veritas","cpe5":"bare_metal_restore","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:28:02.798Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://seer.support.veritas.com/docs/252933.htm"},{"name":"20030225 VERITAS Software Technical Advisory (fwd)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2003-02/0333.html"},{"name":"veritas-bmr-root-access(11418)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11418"},{"name":"6928","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6928"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://seer.support.veritas.com/docs/254442.htm"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-02-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://seer.support.veritas.com/docs/252933.htm"},{"name":"20030225 VERITAS Software Technical Advisory (fwd)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2003-02/0333.html"},{"name":"veritas-bmr-root-access(11418)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11418"},{"name":"6928","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6928"},{"tags":["x_refsource_CONFIRM"],"url":"http://seer.support.veritas.com/docs/254442.htm"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1361","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://seer.support.veritas.com/docs/252933.htm","refsource":"CONFIRM","url":"http://seer.support.veritas.com/docs/252933.htm"},{"name":"20030225 VERITAS Software Technical Advisory (fwd)","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2003-02/0333.html"},{"name":"veritas-bmr-root-access(11418)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11418"},{"name":"6928","refsource":"BID","url":"http://www.securityfocus.com/bid/6928"},{"name":"http://seer.support.veritas.com/docs/254442.htm","refsource":"CONFIRM","url":"http://seer.support.veritas.com/docs/254442.htm"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1361","datePublished":"2007-10-17T01:00:00.000Z","dateReserved":"2007-10-16T00:00:00.000Z","dateUpdated":"2024-08-08T02:28:02.798Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager:3.1.0:*:*:*:*:*:*:*","matchCriteriaId":"6642D8F1-3F9B-4613-A343-B3D4E9849CD9"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager:3.2.1:*:*:*:*:*:*:*","matchCriteriaId":"06E6F6FA-77B8-4FFD-B7B2-6206651BBEAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:veritas:bare_metal_restore:*:*:*:*:*:*:*:*","matchCriteriaId":"EB26CBEA-EF79-439A-8943-34BF416C4E54"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1361","Ordinal":"1","Title":"CVE-2003-1361","CVE":"CVE-2003-1361","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1361","Ordinal":"1","NoteData":"Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.","Type":"Description","Title":"CVE-2003-1361"},{"CveYear":"2003","CveId":"1361","Ordinal":"2","NoteData":"2007-10-16","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1361","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}