Number: AV16-001
Date: 02 January 2016
Purpose
The purpose of this advisory is to bring attention to the recently published security bulletin by IBM.
Assessment
IBM has addressed a vulnerability in IBM Data Protection Extension in the VMware GUI component of IBM Tivoli Storage Manager for Virtual Environments. This privilege escalation vulnerability could allow an authenticated malicious actor, with lower privilege right, to restore an existing virtual machine.
Affected Products:
- Tivoli Storage Manager for Virtual Environments: Data Protection for VMware 7.1.0.0 through 7.1.3.x
- Tivoli Storage FlashCopy Manger for VMware 4.1.0 through 4.1.3.x
CVE Reference:
CVE-2015-7429
Suggested Action
IBM has provided fixes to address this vulnerability.
References:
IBM:
http://www-01.ibm.com/support/docview.wss?uid=swg21973087
CVE Reference:
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-7429