ADSM-L

[ADSM-L] Versions for Web Client security hole

2013-02-04 20:45:28
Subject: [ADSM-L] Versions for Web Client security hole
From: Roger Deschner <rogerd AT UIC DOT EDU>
To: ADSM-L AT VM.MARIST DOT EDU
Date: Mon, 4 Feb 2013 19:42:10 -0600
In http://www-01.ibm.com/support/docview.wss?uid=swg21624118
(CVE-2013-0472), IBM warned us of a security exposure in the TSM Web
Client. That document says the vulnerable versions are 6.3.0.x and
6.4.0.0, and the fixing versions are 6.3.1.0 and 6.4.0.1.

It does not answer the question whether versions prior to 6.3 are
vulnerable, or if this exposure was a new one introduced in 6.3 which is
now fixed. That document implies, but does not say, that prior versions
are not included in this notice, but it does not definitively answer the
question whether they are also at risk.

To simplify my question, are client versions 5.5, 6.1, or 6.2 vulnerable
to this security issue?

Roger Deschner      University of Illinois at Chicago     rogerd AT uic DOT edu
               Academic Computing & Communications Center
======I have not lost my mind -- it is backed up on tape somewhere.=====

<Prev in Thread] Current Thread [Next in Thread>