Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-3976


The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not properly constrain mailbox contents during certain PST restore operations, which allows remote authenticated users to read the personal e-mail of other users in opportunistic circumstances by launching an e-mail client after an administrator performs a multiple-mailbox restore.


Published

2014-03-26T10:55:05.117

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.1 (LOW)

CVSSv2 Vector

AV:N/AC:H/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm data_protection 6.1 Yes
Application ibm data_protection 6.3 Yes
Application ibm flashcopy_manager 2.1 Yes
Application ibm flashcopy_manager 2.2 Yes
Application ibm flashcopy_manager 3.1 Yes
Application ibm tivoli_storage_flashcopy_manager - Yes
Application ibm tivoli_storage_manager_for_mail - Yes

References