CVE-2003-1570
Last modified
CVE-2003-1570 is a vulnerability of currently unknown severity. The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure.". EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tivoli Storage Manager | 5.1.0 |
| Ibm | Tivoli Storage Manager | 5.1.1 |
| Ibm | Tivoli Storage Manager | 5.1.5 |
| Ibm | Tivoli Storage Manager | 5.1.6 |
| Ibm | Tivoli Storage Manager | 5.1.7 |
| Ibm | Tivoli Storage Manager | 5.1.8 |
| Ibm | Tivoli Storage Manager | 5.1.9 |
| Ibm | Tivoli Storage Manager | 5.1.10 |
| Ibm | Tivoli Storage Manager | 5.2.0 |
| Ibm | Tivoli Storage Manager | 5.2.1 |
| Ibm | Tivoli Storage Manager | 6.0 |
References
- http://secunia.com/advisories/34498Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IC37554Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0881Vendor Advisory
- http://secunia.com/advisories/34498Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IC37554Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0881Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-1570?
How severe is CVE-2003-1570?
How do I fix CVE-2003-1570?
Are you affected by CVE-2003-1570?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
