CVE-2013-3976

IBM Tivoli Storage Manager for Mail Data Protection for Exchange < 6.1.3.4 and 6.3 < 6.3.1 - Unauthorized Mailbox Access

Title source: llm
STIX 2.1

Description

The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not properly constrain mailbox contents during certain PST restore operations, which allows remote authenticated users to read the personal e-mail of other users in opportunistic circumstances by launching an e-mail client after an administrator performs a multiple-mailbox restore.

References (3)

Core 3
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC81223
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/84881
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21644407

Scores

EPSS 0.0095
EPSS Percentile 57.5%

Details

CWE
CWE-264
Status published
Products (7)
ibm/data_protection 6.1
ibm/data_protection 6.3
ibm/flashcopy_manager 2.1
ibm/flashcopy_manager 2.2
ibm/flashcopy_manager 3.1
ibm/tivoli_storage_flashcopy_manager
ibm/tivoli_storage_manager_for_mail
Published Mar 26, 2014
Tracked Since Feb 18, 2026