Vulnerabilities > IBM > Tivoli Storage Manager > Low

DATE CVE VULNERABILITY TITLE RISK
2016-07-03 CVE-2016-2894 Information Exposure vulnerability in IBM Tivoli Storage Manager
IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 before 7.1.6 allows local users to obtain sensitive retrieved data from arbitrary accounts in opportunistic circumstances by leveraging previous use of a symlink during archive and retrieve actions.
local
high complexity
ibm CWE-200
2.5
2016-02-15 CVE-2015-7408 Permissions, Privileges, and Access Controls vulnerability in IBM Tivoli Storage Manager
The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.
network
high complexity
ibm CWE-264
3.7