Arbitrary OS Command Execution Vulnerability in IBM Tivoli Storage Manager for Virtual Environments
CVE-2015-7426
10CRITICAL
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 2 January 2016
What is CVE-2015-7426?
The Data Protection extension within the GUI of IBM Tivoli Storage Manager for Virtual Environments (formerly Spectrum Protect for Virtual Environments) and Tivoli Storage FlashCopy Manager for VMware exposes a critical security vulnerability. This flaw allows remote attackers to execute arbitrary operating system commands through unspecified vectors, posing a significant risk to the integrity and security of the affected systems. Users must ensure they are running the latest versions to mitigate this risk effectively.