The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-03-31 11:24
Updated : 2017-08-16 18:29
NVD link : CVE-2003-1570
Mitre link : CVE-2003-1570
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
ibm
- tivoli_storage_manager