CVE-2014-6185
IBM Tivoli Storage Manager 6.3-6.3.2.2, 6.4-6.4.2.1, 7.1-7.1.1.2 - Privilege Escalation via DSO File Loading
Title source: llmDescription
dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict shared-library loading, which allows local users to gain privileges via a crafted DSO file.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98521
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21695715
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT05713
Scores
EPSS
0.0038
EPSS Percentile
31.0%
Details
CWE
CWE-264
Status
published
Products (22)
ibm/tivoli_storage_manager
6.3.0
ibm/tivoli_storage_manager
6.3.0.5
ibm/tivoli_storage_manager
6.3.0.15
ibm/tivoli_storage_manager
6.3.1.2
ibm/tivoli_storage_manager
6.3.2.1
ibm/tivoli_storage_manager
6.3.2.2
ibm/tivoli_storage_manager
6.4.0
ibm/tivoli_storage_manager
6.4.0.1
ibm/tivoli_storage_manager
6.4.0.4
ibm/tivoli_storage_manager
6.4.0.5
... and 12 more
Published
Feb 13, 2015
Tracked Since
Feb 18, 2026