CVE-2008-0247Improper Restriction of Operations within the Bounds of a Memory Buffer in IBM Tivoli Storage Manager Express

Severity
10.0CRITICALNVD
EPSS
36.0%
top 2.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 1

Description

Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4vvc-6vxf-vxg4: Heap-based buffer overflow in the Express Backup Server service (dsmsvc2022-05-01
CVEList
CVE-2008-0247: Heap-based buffer overflow in the Express Backup Server service (dsmsvc2008-01-12
CVE-2008-0247 — IBM vulnerability | cvebase