The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not properly constrain mailbox contents during certain PST restore operations, which allows remote authenticated users to read the personal e-mail of other users in opportunistic circumstances by launching an e-mail client after an administrator performs a multiple-mailbox restore.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2014-03-26T10:00:00
Updated: 2024-08-06T16:30:49.522Z
Reserved: 2013-06-07T00:00:00
Link: CVE-2013-3976
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-03-26T10:55:05.117
Modified: 2024-11-21T01:54:39.067
Link: CVE-2013-3976
Redhat
No data.