Unknown
CVE-2015-4950
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 before 6.1.3.6, 6.3 before 6.3.1.3, 6.4 before 6.4.1.4, and 7.1 before 7.1.0.2; Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Server 2.1, 2.2, 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.1; and Tivoli Storage Manager FastBack for Microsoft Exchange 6.1 before 6.1.5.4 does not ensure that the correct mailbox is selected, which allows remote authenticated users to obtain sensitive information via a duplicate alias name.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- tivoli storage fastback for microsoft exchange 6.1,
- tivoli storage flashcopy manager for microsoft exchange server 2.1,
- tivoli storage flashcopy manager for microsoft exchange server 2.2,
- tivoli storage flashcopy manager for microsoft exchange server 3.1,
- tivoli storage flashcopy manager for microsoft exchange server 3.2,
- tivoli storage flashcopy manager for microsoft exchange server 4.1,
- tivoli storage manager for mail data protection for microsoft exchange server 6.1,
- tivoli storage manager for mail data protection for microsoft exchange server 6.1.1,
- tivoli storage manager for mail data protection for microsoft exchange server 6.1.2,
- tivoli storage manager for mail data protection for microsoft exchange server 6.1.3,
- tivoli storage manager for mail data protection for microsoft exchange server 6.3,
- tivoli storage manager for mail data protection for microsoft exchange server 6.3.1,
- tivoli storage manager for mail data protection for microsoft exchange server 6.4,
- tivoli storage manager for mail data protection for microsoft exchange server 6.4.1,
- tivoli storage manager for mail data protection for microsoft exchange server 7.1
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: