CVE-2013-5371: IBM Tivoli Storage Manager

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The client in IBM Tivoli Storage Manager (TSM) 6.3.1 and 6.4.0 on Windows does not preserve permissions of Resilient File System (ReFS) files across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.

Affected products

  • IBM Tivoli Storage Manager: version 6.3.1 only; version 6.4.0 only

Published 2014-01-23. Last modified 2026-06-16.