CVE-2014-4813
medium
CVSS v3
—
CVSS v2
6.9
VIR risk
6.9
Description
Race condition in the client in IBM Tivoli Storage Manager (TSM) 5.4.0.0 through 5.4.3.6, 5.5.0.0 through 5.5.4.3, 6.1.0.0 through 6.1.5.6, 6.2 before 6.2.5.4, 6.3 before 6.3.2.3, 6.4 before 6.4.2.1, and 7.1 before 7.1.1 on UNIX and Linux allows local users to obtain root privileges via unspecified vectors.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21695652
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| linux-kernel | not-affected | |
Application impact
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT04140
- http://www-01.ibm.com/support/docview.wss?uid=swg21695652
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95389
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT04140
- http://www-01.ibm.com/support/docview.wss?uid=swg21695652
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95389
CWEs
CWE-362
Verify integrity in audit chain (admin only). AS-IS.