Vulnerabilities > IBM > Tivoli Storage Manager > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-11-12 CVE-2018-1786 Resource Exhaustion vulnerability in IBM products
IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state.
network
low complexity
ibm linux microsoft CWE-400
5.0
2017-10-05 CVE-2016-8937 Improper Authentication vulnerability in IBM Tivoli Storage Manager
The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication.
network
low complexity
ibm CWE-287
5.0
2017-03-07 CVE-2016-8940 Information Exposure vulnerability in IBM Tivoli Storage Manager
IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries.
network
low complexity
ibm CWE-200
4.0
2017-02-24 CVE-2016-8998 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM Tivoli Storage Manager
IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on the server.
network
ibm CWE-119
6.0
2017-02-01 CVE-2016-0371 Unspecified vulnerability in IBM Tivoli Storage Manager
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.
local
low complexity
ibm
5.5
2017-02-01 CVE-2016-6045 Cross-Site Request Forgery (CSRF) vulnerability in IBM Tivoli Storage Manager
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
ibm CWE-352
6.8
2017-02-01 CVE-2016-6044 Improper Access Control vulnerability in IBM Tivoli Storage Manager
IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.
network
low complexity
ibm CWE-284
4.0
2017-02-01 CVE-2016-6043 Session Fixation vulnerability in IBM Tivoli Storage Manager
Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.
local
ibm CWE-384
4.4
2016-01-20 CVE-2015-4951 Improper Input Validation vulnerability in IBM Tivoli Storage Manager
Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted Web client URL.
network
low complexity
ibm CWE-20
5.0
2015-02-13 CVE-2014-4813 Race Condition vulnerability in IBM Tivoli Storage Manager
Race condition in the client in IBM Tivoli Storage Manager (TSM) 5.4.0.0 through 5.4.3.6, 5.5.0.0 through 5.5.4.3, 6.1.0.0 through 6.1.5.6, 6.2 before 6.2.5.4, 6.3 before 6.3.2.3, 6.4 before 6.4.2.1, and 7.1 before 7.1.1 on UNIX and Linux allows local users to obtain root privileges via unspecified vectors.
local
ibm linux CWE-362
6.9