IBM Support

Security Bulletin: IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware GUI User May Gain Administrator Authority

Security Bulletin


Summary

A vulnerability exists in the IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware GUI (IBM Spectrum Protect™ for Virtual Environments) where an authenticated user can execute GUI functions that require the Tivoli Storage Manager administrative credentials without having these credentials.

Vulnerability Details

CVEID: CVE-2016-2988
DESCRIPTION: A vulnerability exists in the IBM Tivoli Storage Manager (IBM Spectrum Protect) for Virtual Environments Data Protection for VMware GUI where in limited cases it is possible for authenticated users to execute GUI functions that require the Tivoli Storage Manager(TSM) administrative credentials without having these credentials. After authenticating to the DP for VMware GUI, the user could exercise TSM administrative functions such as Backup Scheduling and Configuration Tasks that they otherwise would not be permitted to use. The vulnerability only applies in configurations where TSM administrative ID credentials have not been stored in the DP for VMware GUI configuration for use by all users. In order to exploit, multiple users must be logged-in to the DP for VMware GUI at the same time, and the exploiter has to be willing to take a malicious action even though they are identifiable from their login credentials.
CVSS Base Score: 8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114050 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)

Affected Products and Versions

The following levels of IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (IBM Spectrum Protect for Virtual Environments) are affected:

  • 7.1.0.0 through 7.1.4.x
  • 6.4.0.0 through 6.4.3.3

Remediation/Fixes

Tivoli Storage Manager for VE: Data Protection for VMware Release First Fixing VRMF Level Client
Platform
Link to Fix / Fix Availability Target
7.1 7.1.6 Linux
Windows
http://www.ibm.com/support/docview.wss?uid=swg24042232
6.4 6.4.3.4 Linux
Windows
http://www.ibm.com/support/docview.wss?uid=swg24041370

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Related information

Acknowledgement

None

Change History

22 August 2016 - Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Document information

More support for: Tivoli Storage Manager for Virtual Environments
Data Protection for VMware

Software version: 6.4, 7.1

Operating system(s): Linux, Windows

Software edition: All Editions

Reference #: 1988781

Modified date: 26 August 2016