CVE-2013-3976
IBM Tivoli Storage Manager for Mail Data Protection for Exchange < 6.1.3.4 and 6.3 < 6.3.1 - Unauthorized Mailbox Access
Title source: llmDescription
The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not properly constrain mailbox contents during certain PST restore operations, which allows remote authenticated users to read the personal e-mail of other users in opportunistic circumstances by launching an e-mail client after an administrator performs a multiple-mailbox restore.
References (3)
Core 3
Core References
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC81223
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/84881
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21644407
Scores
EPSS
0.0095
EPSS Percentile
57.5%
Details
CWE
CWE-264
Status
published
Products (7)
ibm/data_protection
6.1
ibm/data_protection
6.3
ibm/flashcopy_manager
2.1
ibm/flashcopy_manager
2.2
ibm/flashcopy_manager
3.1
ibm/tivoli_storage_flashcopy_manager
ibm/tivoli_storage_manager_for_mail
Published
Mar 26, 2014
Tracked Since
Feb 18, 2026