CVE-2013-3976

Severity

21%

Complexity

39%

Confidentiality

48%

Per: http://www-01.ibm.com/support/docview.wss?uid=swg21644407 "AFFECTED PRODUCTS AND VERSIONS: Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 and 6.3 Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Sever 2.1, 2.2, and 3.1"

The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not properly constrain mailbox contents during certain PST restore operations, which allows remote authenticated users to read the personal e-mail of other users in opportunistic circumstances by launching an e-mail client after an administrator performs a multiple-mailbox restore.

Per: http://www-01.ibm.com/support/docview.wss?uid=swg21644407 "AFFECTED PRODUCTS AND VERSIONS: Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 and 6.3 Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Sever 2.1, 2.2, and 3.1"

CVSS 2.0 Base Score 2.1. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (AV:N/AC:H/Au:S/C:P/I:N/A:N).

Overview

Type

IBM

First reported 11 years ago

2014-03-26 10:55:00

Last updated 7 years ago

2017-08-29 01:33:00

Affected Software

IBM Data Protection for Microsoft Exchange Server 6.1

6.1
exchange_server

IBM Data Protection for Microsoft Exchange Server 6.3

6.3
exchange_server

IBM FlashCopy Manager for Microsoft Exchange Server 2.1

2.1
exchange_server

IBM FlashCopy Manager for Microsoft Exchange Server 2.2

2.2
exchange_server

IBM FlashCopy Manager for Microsoft Exchange Server 3.1

3.1
exchange_server

IBM Tivoli Storage FlashCopy Manager

IBM Tivoli Storage Manager for Mail

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.