RULE(RULE ID:710194)

Rule General Information
Release Date: 2019-12-30
Rule Name: IBM Tivoli Storage Manager FastBack Server Opcode 1329 Directory Traversal Vulnerability (CVE-2015-1941)
Severity:
CVE ID:
Rule Protection Details
Description: >A directory traversal vulnerability exists in IBM Tivoli Storage Manager FastBack Server 6.1 before 6.1.12. The vulnerability is due to insufficient input validation of parameters in opcode 1329 requests. A remote unauthenticated attacker could exploit this vulnerability by sending crafted requests to port 11460/TCP. Successful exploitation results in disclosing information under the security context of System.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows
Reference: SecurityFocusBID:75446
SecurityTrackerID:1032773
ZeroDayInitiative:ZDI-15-268
http://www-01.ibm.com/support/docview.wss?uid=swg21959398
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www-01.ibm.com/support/docview.wss?uid=swg21959398