Description
The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 3.1 before 3.1.1.3, 3.2 before 3.2.0.6, and 4.1 before 4.1.4 allows remote attackers to obtain administrative privileges via a crafted URL that triggers back-end function execution.
Published: 2016-02-21
Score: 10.0 Critical
EPSS: 9.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2015-7349 The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 3.1 before 3.1.1.3, 3.2 before 3.2.0.6, and 4.1 before 4.1.4 allows remote attackers to obtain administrative privileges via a crafted URL that triggers back-end function execution.
History

No history.

Subscriptions

Ibm Tivoli Storage Flashcopy Manager For Vmware Tivoli Storage Manager For Virtual Environments Data Protection For Vmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-06T07:51:27.272Z

Reserved: 2015-09-29T00:00:00.000Z

Link: CVE-2015-7425

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-02-21T18:59:00.113

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-7425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses