2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2015-4950" ,
"sourceIdentifier" : "psirt@us.ibm.com" ,
"published" : "2015-08-23T14:59:01.677" ,
2024-11-23 01:05:45 +00:00
"lastModified" : "2024-11-21T02:32:05.340" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 before 6.1.3.6, 6.3 before 6.3.1.3, 6.4 before 6.4.1.4, and 7.1 before 7.1.0.2; Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Server 2.1, 2.2, 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.1; and Tivoli Storage Manager FastBack for Microsoft Exchange 6.1 before 6.1.5.4 does not ensure that the correct mailbox is selected, which allows remote authenticated users to obtain sensitive information via a duplicate alias name."
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad en la aplicaci\u00f3n del restablecimiento del buz\u00f3n de correo en IBM Tivoli Storage Manager for Mail: protecci\u00f3n de datos para Microsoft Exchange Server 6.1 en versiones anteriores a 6.1.3.6, 6.3 en versiones anteriores a 6.3.1.3, 6.4 en versiones anteriores a 6.4.1.4 y 7.1 en versiones anteriores a 7.1.0.2; Tivoli Storage FlashCopy Manager: FlashCopy Manager para Microsoft Exchange Server 2.1, 2.2, 3.1 en versiones anteriores a 3.1.1.5, 3.2 en versiones anteriores a 3.2.1.7 y 4.1 en versiones anteriores a 4.1.1; y Tivoli Storage Manager FastBack para Microsoft Exchange 6.1 en versiones anteriores a 6.1.5.4 no asegura que sea seleccionado el buz\u00f3n de correo correcto, lo que permite a usuarios remotos autenticados obtener informaci\u00f3n sensible a trav\u00e9s de apodo duplicado."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N" ,
2024-11-23 01:05:45 +00:00
"baseScore" : 4.0 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "SINGLE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "NONE" ,
2024-11-23 01:05:45 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.0 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-200"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_fastback_for_microsoft_exchange:6.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "844CCE00-B098-432C-85C7-B98C6FF0003B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_microsoft_exchange_server:2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "509704C7-A2F0-47DE-859B-00F77CA22B27"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_microsoft_exchange_server:2.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4B1F5CC5-2A7F-4CC4-8CA2-95BA3933B42B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_microsoft_exchange_server:3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8CA5985C-FC33-4DE0-82D6-66E4CB00F3F7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_microsoft_exchange_server:3.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "51A513FE-4975-49F7-91B4-9614855F6754"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_flashcopy_manager_for_microsoft_exchange_server:4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D515C201-2243-4459-8110-5707A3B016EC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "44FC12F3-39C7-49FD-BB60-7C21607C77DB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "881ACFC0-4354-448A-A9BB-2F5BB72358C3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EC6978D5-4AF1-48D6-A7D5-E0158F4C8DE3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.1.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "24E7AD18-232C-4996-931F-72545CB38B3A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B5124F05-4C0E-422A-8CB3-E93826767ACF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "144ED09E-DE01-450C-84DF-DEFE9E6EE48B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C1B8D631-0EBE-47AB-AACA-9A0BA1077C1D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:6.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D76E0E49-1486-4518-BD46-826786BAA937"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server:7.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9B3CB08F-D41F-4441-9078-2C9E68EC2EDD"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT04251" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT04252" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21963629" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.securitytracker.com/id/1033652" ,
"source" : "psirt@us.ibm.com"
2024-11-23 01:05:45 +00:00
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT04251" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT04252" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21963629" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.securitytracker.com/id/1033652" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}