Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78rh-h9j3-q64m

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.

The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.

EPSS

Процентиль: 41%
0.00196
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
почти 10 лет назад

The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.

EPSS

Процентиль: 41%
0.00196
Низкий

3.7 Low

CVSS3