The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21680453 | Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IC96095 | Broken Link |
http://secunia.com/advisories/60482 | Third Party Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/89054 | VDB Entry Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Information
Published : 2014-08-26 03:55
Updated : 2020-10-29 13:19
NVD link : CVE-2013-6335
Mitre link : CVE-2013-6335
JSON object : View
CWE
CWE-281
Improper Preservation of Permissions
Products Affected
ibm
- aix
- tivoli_storage_manager
hp
- hp-ux
linux
- linux_kernel
oracle
- solaris