Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-6714


The FlashCopy Manager for VMware component in IBM Tivoli Storage FlashCopy Manager 3.1 through 4.1.0.1 does not properly check authorization for backup and restore operations, which allows local users to obtain sensitive VM data or cause a denial of service (data overwrite or disk consumption) via unspecified GUI actions.


Published

2014-05-26T19:55:04.200

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.1 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

2.7

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm tivoli_storage_flashcopy_manager 3.1.0 Yes
Application ibm tivoli_storage_flashcopy_manager 3.1.1 Yes
Application ibm tivoli_storage_flashcopy_manager 3.2.0 Yes
Application ibm tivoli_storage_flashcopy_manager 3.2.1 Yes
Application ibm tivoli_storage_flashcopy_manager 4.1.0 Yes
Application ibm tivoli_storage_flashcopy_manager 4.1.0.1 Yes

References