CVE-2015-4950
Published Aug 23, 2015
Last updated 8 years ago
Overview
- Description
- The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 before 6.1.3.6, 6.3 before 6.3.1.3, 6.4 before 6.4.1.4, and 7.1 before 7.1.0.2; Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Server 2.1, 2.2, 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.1; and Tivoli Storage Manager FastBack for Microsoft Exchange 6.1 before 6.1.5.4 does not ensure that the correct mailbox is selected, which allows remote authenticated users to obtain sensitive information via a duplicate alias name.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:tivoli_storage_fastback_for_microsoft_exchange:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "844CCE00-B098-432C-85C7-B98C6FF0003B" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_microsoft_exchange_server:2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "509704C7-A2F0-47DE-859B-00F77CA22B27" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_microsoft_exchange_server:2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B1F5CC5-2A7F-4CC4-8CA2-95BA3933B42B" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_microsoft_exchange_server:3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CA5985C-FC33-4DE0-82D6-66E4CB00F3F7" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_microsoft_exchange_server:3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51A513FE-4975-49F7-91B4-9614855F6754" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_microsoft_exchange_server:4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D515C201-2243-4459-8110-5707A3B016EC" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44FC12F3-39C7-49FD-BB60-7C21607C77DB" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "881ACFC0-4354-448A-A9BB-2F5BB72358C3" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC6978D5-4AF1-48D6-A7D5-E0158F4C8DE3" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24E7AD18-232C-4996-931F-72545CB38B3A" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5124F05-4C0E-422A-8CB3-E93826767ACF" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "144ED09E-DE01-450C-84DF-DEFE9E6EE48B" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1B8D631-0EBE-47AB-AACA-9A0BA1077C1D" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D76E0E49-1486-4518-BD46-826786BAA937" }, { "criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B3CB08F-D41F-4441-9078-2C9E68EC2EDD" } ], "operator": "OR" } ] } ]