AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-3976

LOW · CVSS 2.1 EPSS 0.95%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-03-26 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.1. It affects Exchange. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2013-3976
Severity
LOW
CVSS
2.1
EPSS
0.95%
Exchange

Original NVD Description

The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not properly constrain mailbox contents during certain PST restore operations, which allows remote authenticated users to read the personal e-mail of other users in opportunistic circumstances by launching an e-mail client after an administrator performs a multiple-mailbox restore.