IBM Support

Security Bulletin: Security vulnerabilities have been identified in the IBM Spectrum Protect (formerly Tivoli Storage Manager) Client that affect multiple IBM Spectrum Protect (formerly Tivoli Storage Manager) products

Security Bulletin


Summary

The IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API is used as a component of IBM Spectrum Protect Snapshot (formerly Tivoli Storage FlashCopy Manager) for Windows, IBM Spectrum Protect (formerly Tivoli Storage Manager) for Databases, IBM Spectrum Protect (formerly Tivoli Storage Manager) for Mail, and IBM Spectrum Protect (formerly Tivoli Storage Manager) for Enterprise Resource Planning. Information about security vulnerabilities affecting the IBM Spectrum Protect (Tivoli Storage Manager) Client/API have been published in security bulletins.

Vulnerability Details

Consult the following security bulletins for vulnerability details and information about the IBM Spectrum Protect (Tivoli Storage Manager) Client/API fixes:
- http://www.ibm.com/support/docview.wss?uid=swg22007935
- http://www.ibm.com/support/docview.wss?uid=swg22003738

Affected Products and Versions

Principal Product and Version(s)

Affected Supporting Product and Version
IBM Spectrum Protect Snapshot (formerly Tivoli Storage FlashCopy Manager) for Windows version 8.1 IBM Spectrum Protect (formerly Tivoli Storage Manager) Client version 8.1
IBM Spectrum Protect Snapshot (formerly Tivoli Storage FlashCopy Manager) for Windows version 4.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client version 7.1.
Tivoli Storage FlashCopy Manager for Windows version 3.2 and below are EOS. IBM recommends upgrading to a supported level.Tivoli Storage Manager Client version 6.4 and below are EOS.
IBM recommends upgrading to a supported level.
Note: Within the IBM Spectrum Protect Snapshot (Tivoli Storage FlashCopy Manager) on Windows product, the IBM Spectrum Protect (Tivoli Storage Manager) Client is also referred to as the IBM Spectrum Protect Snapshot (FlashCopy Manager) VSS Requestor component.

Principal Product and Version(s)Affected Supporting Product and Version
IBM Spectrum Protect for Databases (formerly Tivoli Storage Manager for Databases): Data Protection for Microsoft SQL Server version 8.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 8.1
IBM Spectrum Protect for Databases (formerly Tivoli Storage Manager for Databases): Data Protection for Microsoft SQL Server version 7.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server version 6.4 and below are EOS. IBM recommends upgrading to a supported level.Tivoli Storage Manager Client/API version 6.4 and below are EOS. IBM recommends upgrading to a supported level.

Principal Product and Version(s)Affected Supporting Product and Version
IBM Spectrum Protect for Databases (formerly Tivoli Storage Manager for Databases): Data Protection for Oracle version 8.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 8.1
IBM Spectrum Protect for Databases (formerly Tivoli Storage Manager for Databases): Data Protection for Oracle version 7.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage Manager for Databases: Data Protection for Oracle version 6.4 and below are EOS. IBM recommends upgrading to a supported level.Tivoli Storage Manager Client/API version 6.4 and below are EOS. IBM recommends upgrading to a supported level.


Principal Product and Version(s)Affected Supporting Product and Version
IBM Spectrum Protect for Mail (formerly Tivoli Storage Manager for Mail): Data Protection for Microsoft Exchange Server version 8.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 8.1
IBM Spectrum Protect for Mail (formerly Tivoli Storage Manager for Mail): Data Protection for Microsoft Exchange Server version 7.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server version 6.4 and below are EOS. IBM recommends upgrading to a supported level.Tivoli Storage Manager Client/API version 6.4 and below are EOS. IBM recommends upgrading to a supported level.


Principal Product and Version(s)Affected Supporting Product and Version
Tivoli Storage Manager for Mail: Data Protection for Domino on Windows version 7.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage Manager for Mail: Data Protection for Domino on Windows version 6.4 and below are EOS. IBM recommends upgrading to a supported level.Tivoli Storage Manager Client/API version 6.4 and below are EOS. IBM recommends upgrading to a supported level.

Principal Product and Version(s)Affected Supporting Product and Version
IBM Spectrum Protect for Enterprise Resource Planning (formerly Tivoli Storage Manager for Enterprise Resource Planning): Data Protection for SAP for Oracle version 8.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 8.1
IBM Spectrum Protect for Enterprise Resource Planning (formerly Tivoli Storage Manager for Enterprise Resource Planning): Data Protection for SAP for Oracle version 7.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage Manager for Enterprise Resource Planning: Data Protection for SAP for Oracle 6.4 and below are EOS. IBM recommends upgrading to a supported level.Tivoli Storage Manager Client/API version 6.4 and below are EOS. IBM recommends upgrading to a supported level.


Principal Product and Version(s)Affected Supporting Product and Version
IBM Spectrum Protect for Enterprise Resource Planning (formerly Tivoli Storage Manager for Enterprise Resource Planning): Data Protection for SAP for DB2 version 8.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 8.1
IBM Spectrum Protect for Enterprise Resource Planning (formerly Tivoli Storage Manager for Enterprise Resource Planning): Data Protection for SAP for DB2 version 7.1IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage Manager for Enterprise Resource Planning: Data Protection for SAP for DB2 6.4 and below are EOS. IBM recommends upgrading to a supported level.Tivoli Storage Manager Client/API version 6.4 and below are EOS. IBM recommends upgrading to a supported level.



Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

02 October 2017 - Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSERFV","label":"IBM Spectrum Protect Snapshot"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":"--","Platform":[{"code":"PF033","label":"Windows"}],"Version":"4.1.3;4.1.4;4.1.6;8.1.0","Edition":"All Editions","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"SSER7G","label":"IBM Spectrum Protect for Databases"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":" ","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"7.1.3;7.1.4;7.1.6;8.1.0","Edition":"All Editions","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"SSTFZR","label":"Tivoli Storage Manager for Databases"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":" ","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"6.4;7.1","Edition":"All Editions","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"SSERBW","label":"IBM Spectrum Protect for Mail"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":" ","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"7.1.3;7.1.4;7.1.6;8.1.0","Edition":"All Editions","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"SSTG2D","label":"Tivoli Storage Manager for Mail"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":" ","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"6.4;7.1","Edition":"All Editions","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"SSER83","label":"IBM Spectrum Protect for Enterprise Resource Planning"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":" ","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"7.1.3;7.1.4;7.1.6;8.1.0","Edition":"All Editions","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"SSZHVN","label":"Tivoli Storage Manager for Enterprise Resource Planning"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":" ","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"6.4;7.1.3","Edition":"All Editions","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"SSERFV","label":"IBM Spectrum Protect Snapshot"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":" ","Platform":[{"code":"PF033","label":"Windows"}],"Version":"4.1.3;4.1.4;4.1.6;8.1.0","Edition":"All Editions","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"SS36V9","label":"Tivoli Storage FlashCopy Manager"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":" ","Platform":[{"code":"PF033","label":"Windows"}],"Version":"3.2;4.1","Edition":"All Editions","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
01 February 2022

UID

swg22008305