4
CVSSv2

CVE-2015-4950

Published: 23/08/2015 Updated: 08/12/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 prior to 6.1.3.6, 6.3 prior to 6.3.1.3, 6.4 prior to 6.4.1.4, and 7.1 prior to 7.1.0.2; Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Server 2.1, 2.2, 3.1 prior to 3.1.1.5, 3.2 prior to 3.2.1.7, and 4.1 prior to 4.1.1; and Tivoli Storage Manager FastBack for Microsoft Exchange 6.1 prior to 6.1.5.4 does not ensure that the correct mailbox is selected, which allows remote authenticated users to obtain sensitive information via a duplicate alias name.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm tivoli storage manager for mail data protection for microsoft exchange server 6.1

ibm tivoli storage manager for mail data protection for microsoft exchange server 6.4.1

ibm tivoli storage manager for mail data protection for microsoft exchange server 7.1

ibm tivoli storage manager for mail data protection for microsoft exchange server 6.1.3

ibm tivoli storage manager for mail data protection for microsoft exchange server 6.3

ibm tivoli storage flashcopy manager for microsoft exchange server 3.1

ibm tivoli storage flashcopy manager for microsoft exchange server 3.2

ibm tivoli storage manager for mail data protection for microsoft exchange server 6.3.1

ibm tivoli storage manager for mail data protection for microsoft exchange server 6.4

ibm tivoli storage flashcopy manager for microsoft exchange server 4.1

ibm tivoli storage fastback for microsoft exchange 6.1

ibm tivoli storage manager for mail data protection for microsoft exchange server 6.1.1

ibm tivoli storage manager for mail data protection for microsoft exchange server 6.1.2

ibm tivoli storage flashcopy manager for microsoft exchange server 2.1

ibm tivoli storage flashcopy manager for microsoft exchange server 2.2