IBM Tivoli Storage Manager Client CVE-2013-5371 Insecure File Permissions Vulnerability
BID:65102
Info
IBM Tivoli Storage Manager Client CVE-2013-5371 Insecure File Permissions Vulnerability
| Bugtraq ID: | 65102 |
| Class: | Design Error |
| CVE: |
CVE-2013-5371 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 22 2014 12:00AM |
| Updated: | Jan 22 2014 12:00AM |
| Credit: | Vendor reported this issue. |
| Vulnerable: |
IBM IBM Tivoli Storage Manager Client 6.4 IBM IBM Tivoli Storage Manager Client 6.3.1.0 |
| Not Vulnerable: |
IBM IBM Tivoli Storage Manager Client 7.1 |
Discussion
IBM Tivoli Storage Manager Client CVE-2013-5371 Insecure File Permissions Vulnerability
IBM Tivoli Storage Manager Client is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information and overwrite certain files. Information obtained may aid in other attacks.
IBM Tivoli Storage Manager Client versions 6.3.1 and 6.4.0 are vulnerable.
IBM Tivoli Storage Manager Client is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information and overwrite certain files. Information obtained may aid in other attacks.
IBM Tivoli Storage Manager Client versions 6.3.1 and 6.4.0 are vulnerable.
Exploit / POC
IBM Tivoli Storage Manager Client CVE-2013-5371 Insecure File Permissions Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
IBM Tivoli Storage Manager Client CVE-2013-5371 Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Tivoli Storage Manager Client CVE-2013-5371 Insecure File Permissions Vulnerability
References:
References: