Re: Fixing level for ASNODENAME vulnerability

2016-02-26 Thread Del Hoobler
I was able to get some more details. Here they are: == The problem is that all client sessions which use ASNODENAME and have authority to use ASNODENAME, will run as authorized sessions. According to the doc, sessions using ASNODENAME must be run as authoriz

Re: Fixing level for ASNODENAME vulnerability

2016-02-26 Thread Krzysztof Przygoda
Hi This is really good question. If fact current description is not very clear. Anyone could provide better one or some example scenario to know which data/config is affected? Thanks in advance Krzysztof 2016-02-25 13:04 GMT+01:00 Henrik Ahlgren : > Is the IBM Security Bulletin correct when it d

Re: Fixing level for ASNODENAME vulnerability

2016-02-25 Thread Henrik Ahlgren
Is the IBM Security Bulletin correct when it does not list Windows as a vulnerable platform? BTW, where can I find a more detailed description about what does this mean exactly: "The Tivoli Storage Manager server fails to adequately check the authorization of client sessions using the ASNODENAME o

Re: Fixing level for ASNODENAME vulnerability

2016-02-24 Thread David Ehresman
I read the table to say that there is a fix for TSM 6.1 but it is not available for general download and that you have to contact support to get the fix. David -Original Message- From: ADSM: Dist Stor Manager [mailto:ADSM-L@VM.MARIST.EDU] On Behalf Of Thomas Denier Sent: Wednesday, Febr