CVE-2015-4950
https://notcve.org/view.php?id=CVE-2015-4950
The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 before 6.1.3.6, 6.3 before 6.3.1.3, 6.4 before 6.4.1.4, and 7.1 before 7.1.0.2; Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Server 2.1, 2.2, 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.1; and Tivoli Storage Manager FastBack for Microsoft Exchange 6.1 before 6.1.5.4 does not ensure that the correct mailbox is selected, which allows remote authenticated users to obtain sensitive information via a duplicate alias name. Vulnerabilidad en la aplicación del restablecimiento del buzón de correo en IBM Tivoli Storage Manager for Mail: protección de datos para Microsoft Exchange Server 6.1 en versiones anteriores a 6.1.3.6, 6.3 en versiones anteriores a 6.3.1.3, 6.4 en versiones anteriores a 6.4.1.4 y 7.1 en versiones anteriores a 7.1.0.2; Tivoli Storage FlashCopy Manager: FlashCopy Manager para Microsoft Exchange Server 2.1, 2.2, 3.1 en versiones anteriores a 3.1.1.5, 3.2 en versiones anteriores a 3.2.1.7 y 4.1 en versiones anteriores a 4.1.1; y Tivoli Storage Manager FastBack para Microsoft Exchange 6.1 en versiones anteriores a 6.1.5.4 no asegura que sea seleccionado el buzón de correo correcto, lo que permite a usuarios remotos autenticados obtener información sensible a través de apodo duplicado. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT04251 http://www-01.ibm.com/support/docview.wss?uid=swg1IT04252 http://www-01.ibm.com/support/docview.wss?uid=swg21963629 http://www.securitytracker.com/id/1033652 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2015-6557
https://notcve.org/view.php?id=CVE-2015-6557
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949. Vulnerabilidad en IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server en 5.5 en versiones anteriores a 5.5.6.1, en 6.3 en versiones anteriores a 6.3.1.5, en 6.4 en versiones anteriores a 6.4.1.7 y en 7.1 en versiones anteriores a 7.1.2, Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server en en 5.5 en versiones anteriores a 5.5.1.1, en 6.1 en versiones anteriores a 6.1.3.7, en 6.3 en versiones anteriores a 6.3.1.5, en 6.4 en versiones anteriores a 6.4.1.7 y en 7.1 en versiones anteriores a 7.1.2 y en Tivoli Storage FlashCopy Manager en 3.1 en versiones anteriores a 3.1.1.5, en 3.2 en versiones anteriores a 3.2.1.7 y en 4.1 en versiones anteriores a 4.1.2, cuando se utiliza el rastreo de aplicaciones, colocando las contraseñas en texto plano en mensajes de excepción, permite a atacantes físicamente próximos obtener información sensible mediante la lectura de salida del rastreo, una vulnerabilidad diferente a CVE-2015-4949. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT03480 http://www-01.ibm.com/support/docview.wss?uid=swg21963630 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2015-4949
https://notcve.org/view.php?id=CVE-2015-4949
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 7.1 before 7.1.2, Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 7.1 before 7.1.2, and Tivoli Storage FlashCopy Manager 4.1 before 4.1.2 place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading GUI pop-up windows, a different vulnerability than CVE-2015-6557. Vulnerabilidad en IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server en 7.1 en versiones anteriores a 7.1.2, Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server en 7.1 en versiones anteriores a 7.1.2 y en Tivoli Storage FlashCopy Manager en 4.1 en versiones anteriores a 4.1.2, coloca las contraseñas en texto plano en mensajes de excepción, permite a atacantes físicamente próximos obtener información sensible mediante la lectura de las ventanas emergentes GUI, una vulnerabilidad diferente a CVE-2015-6557. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT03480 http://www-01.ibm.com/support/docview.wss?uid=swg21963630 http://www.securitytracker.com/id/1033270 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2015-4934 – IBM Tivoli Storage Manager FastBack Server Opcode 8192 Stack Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2015-4934
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4933, and CVE-2015-4935. Desbordamiento del buffer basado en pila en el servidor en IBM Tivoli Storage Manager FastBack 6.1 en versiones anteriores a 6.1.12.1, permite a atacantes remotos ejecutar código arbitrario a través de un paquete manipulado, una vulnerabilidad diferente a CVE-2015-4931, CVE-2015-4932, CVE-2015-4933 y CVE-2015-4935. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Tivoli Storage Manager FastBack. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of opcode 8192. By sending a crafted packet on TCP port 11460, an attacker is able to cause a stack buffer overflow when handling SymbolOperation debug dispatching. • http://www-01.ibm.com/support/docview.wss?uid=swg21961928 http://www.securityfocus.com/bid/76109 http://www.zerodayinitiative.com/advisories/ZDI-15-376 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-4932 – IBM Tivoli Storage Manager FastBack Server Opcode 1365 Files Restore Agents Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2015-4932
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935. Desbordamiento del buffer basado en pila en el servidor en IBM Tivoli Storage Manager FastBack 6.1 en versiones anteriores a 6.1.12.1, permite a atacantes remotos ejecutar código arbitrario a través de un paquete manipulado, una vulnerabilidad diferente a CVE-2015-4931, CVE-2015-4933, CVE-2015-4934 y CVE-2015-4935. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Tivoli Storage Manager FastBack. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of opcode 1365. By sending a crafted packet on TCP port 11460, an attacker is able to cause a stack buffer overflow when handling a Files Restore Agents list. • http://www-01.ibm.com/support/docview.wss?uid=swg21961928 http://www.securityfocus.com/bid/76106 http://www.zerodayinitiative.com/advisories/ZDI-15-373 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •