Vulnerability Details CVE-2015-7408
The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.1%
CVSS Severity
CVSS v3 Score 3.7
CVSS v2 Score 2.6
Products affected by CVE-2015-7408
-
cpe:2.3:a:ibm:tivoli_storage_manager:5.5.0.0
-
cpe:2.3:a:ibm:tivoli_storage_manager:6.1.0.0
-
cpe:2.3:a:ibm:tivoli_storage_manager:6.2.0.0
-
cpe:2.3:a:ibm:tivoli_storage_manager:6.3.3.0
-
cpe:2.3:a:ibm:tivoli_storage_manager:6.3.4.0
-
cpe:2.3:a:ibm:tivoli_storage_manager:6.3.5.0
-
cpe:2.3:a:ibm:tivoli_storage_manager:7.1.0.0
-
cpe:2.3:a:ibm:tivoli_storage_manager:7.1.0.1
-
cpe:2.3:a:ibm:tivoli_storage_manager:7.1.0.2
-
cpe:2.3:a:ibm:tivoli_storage_manager:7.1.0.3