The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21680453 | Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IC96095 | Broken Link |
http://secunia.com/advisories/60482 | Third Party Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/89054 | VDB Entry Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
No history.
Information
Published : 2014-08-26 10:55
Updated : 2020-10-29 20:19
NVD link : CVE-2013-6335
Mitre link : CVE-2013-6335
JSON object : View
Products Affected
oracle
- solaris
hp
- hp-ux
linux
- linux_kernel
ibm
- tivoli_storage_manager
- aix
CWE
CWE-281
Improper Preservation of Permissions