CVE-2015-7408: IBM Tivoli Storage Manager
Low severity, CVSS 3.7. EPSS: 0.9% chance of exploitation in the next 30 days.
The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.
Affected products
- IBM Tivoli Storage Manager: version 5.5.0.0 only; version 6.1.0.0 only; version 6.2.0.0 only; version 6.3.3.0 only; version 6.3.4.0 only; version 6.3.5.0 only; …
Published 2016-02-15. Last modified 2026-06-17.