
CVE-2014-4813
https://notcve.org/view.php?id=CVE-2014-4813
13 Feb 2015 — Race condition in the client in IBM Tivoli Storage Manager (TSM) 5.4.0.0 through 5.4.3.6, 5.5.0.0 through 5.5.4.3, 6.1.0.0 through 6.1.5.6, 6.2 before 6.2.5.4, 6.3 before 6.3.2.3, 6.4 before 6.4.2.1, and 7.1 before 7.1.1 on UNIX and Linux allows local users to obtain root privileges via unspecified vectors. Condición de carrera en el cliente en IBM Tivoli Storage Manager (TSM) 5.4.0.0 hasta 5.4.3.6, 5.5.0.0 hasta 5.5.4.3, 6.1.0.0 hasta 6.1.5.6, 6.2 anterior a 6.2.5.4, 6.3 anterior a 6.3.2.3, 6.4 anterior a ... • http://www-01.ibm.com/support/docview.wss?uid=swg1IT04140 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVE-2014-6185
https://notcve.org/view.php?id=CVE-2014-6185
13 Feb 2015 — dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict shared-library loading, which allows local users to gain privileges via a crafted DSO file. dsmtca en el cliente en IBM Tivoli Storage Manager (TSM) 6.3 anterior a 6.3.2.3, 6.4 anterior a 6.4.2.2, y 7.1 anterior a 7.1.1.3 no restringe correctamente la carga de la libraría compartida, lo que permite a usuarios locales ganar privilegios a través de un fichero DSO m... • http://www-01.ibm.com/support/docview.wss?uid=swg1IT05713 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-4817
https://notcve.org/view.php?id=CVE-2014-4817
18 Nov 2014 — The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attackers to bypass intended access restrictions and replace file backups by using a certain backup option in conjunction with a filename that matches a previously used filename. El servidor en IBM Tivoli Storage Manager (TSM) 5.x y 6.x anterior a 6.3.5.10 y 7.x anterior a 7.1.1.100 permitiría a atacantes remotos eludir las restricciones de acceso y reemplazar las copias de seguridad de archivos... • http://www-01.ibm.com/support/docview.wss?uid=swg1IT04884 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-6335
https://notcve.org/view.php?id=CVE-2013-6335
26 Aug 2014 — The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations. El cliente Backup-Archive en IBM Tivoli Storage Manager (TSM) for Space Management 5.x y 6.x... • http://secunia.com/advisories/60482 • CWE-281: Improper Preservation of Permissions •

CVE-2014-0876
https://notcve.org/view.php?id=CVE-2014-0876
17 Aug 2014 — Buffer overflow in the Java GUI Configuration Wizard and Preferences Editor in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.2.5.2, 6.3.x before 6.3.2, and 6.4.x before 6.4.2 on Windows and OS X allows local users to cause a denial of service (application crash or hang) via unspecified vectors. Desbordamiento de buffer en Java GUI Configuration Wizard y Preferences Editor en el cliente del archivo de la copia de seguridad en IBM Tivoli Storage Manager (TSM) 5.x y 6.x ant... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC95875 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-5371
https://notcve.org/view.php?id=CVE-2013-5371
23 Jan 2014 — The client in IBM Tivoli Storage Manager (TSM) 6.3.1 and 6.4.0 on Windows does not preserve permissions of Resilient File System (ReFS) files across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations. El cliente en Tivoli Storage Manager (TSM) de IBM versiones 6.3.1 y 6.4.0 en Windows, no conserva los permisos del Sistema de Archivos Resistente (ReFS) en las operaciones de copia de seguridad y restauración, lo que permite a los u... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC92933 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-0471
https://notcve.org/view.php?id=CVE-2013-0471
21 Feb 2013 — The traditional scheduler in the client in IBM Tivoli Storage Manager (TSM) before 6.2.5.0, 6.3 before 6.3.1.0, and 6.4 before 6.4.0.1, when Prompted mode is enabled, allows remote attackers to cause a denial of service (scheduling outage) via unspecified vectors. El planificador tradicional en el cliente de IBM Tivoli Storage Manager (TSM) antes de v6.2.5.0, v6.3.1.0 antes de v6.3 y v6.4 antes de v6.4.0.1, cuando la modalidad de petición está activada, permite a atacantes remotos provocar una denegación de... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC87331 •

CVE-2013-0472
https://notcve.org/view.php?id=CVE-2013-0472
21 Feb 2013 — The Web GUI in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.1.0 and 6.4 before 6.4.0.1 allows man-in-the-middle attackers to obtain unspecified client access, and consequently obtain unspecified server access, via unknown vectors. La interfaz gráfica de usuario Web en el cliente de IBM Tivoli Storage Manager (TSM) v6,3 antes de v6.3.1.0 y v6,4 antes de v6.4.0.1 permite ataques de man-in-the-middle para obtener acceso de clientes no especificados, y por lo tanto obtener acceso al servidor si... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC87210 •