Skip to main content

Vendor/product archive

ibm / tivoli_storage_manager CVEs

Beta · best-effort

50 CVEs tagged to ibm / tivoli_storage_manager8 Critical, 17 High, 16 Medium, 9 Low, 0 Unrated.

CVE-2020-28198

Published May 6, 2021

The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow. No…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1378

Published Oct 5, 2017

IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtaine…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1339

Published Oct 5, 2017

IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum p…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1301

Published Oct 5, 2017

IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local at…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8937

Published Oct 5, 2017

The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information duri…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-8939

Published Jun 7, 2017

IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force I…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8916

Published May 5, 2017

IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8940

Published Mar 7, 2017

IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8998

Published Feb 24, 2017

IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execut…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6046

Published Feb 1, 2017

IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6045

Published Feb 1, 2017

IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted fr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6044

Published Feb 1, 2017

IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security pol…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6043

Published Feb 1, 2017

Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5985

Published Feb 1, 2017

The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2894

Published Jul 3, 2016

IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 before 7.1.6 allows local users to obtain sensitive retrieved da…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-7408

Published Feb 15, 2016

The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allo…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-4951

Published Jan 20, 2016

Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 allows re…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4927

Published Nov 4, 2015

The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions fo…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4818

Published Feb 24, 2015

dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4.x, 5.5.x, 6.x before 6.4.3, and 7.1.x before 7.1.2 allows local users to discover the backup/restore encryption-key pa…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 50 CVEsPage 1 of 2