CVE-2010-3059
published 2010-08-20CVE-2010-3059: Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.53%
71.7th percentile
Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to read and modify data, and possibly have other impact, via an unspecified command.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3frf-gw23-35mh: Unspecified vulnerability in IBM Tivoli Storage Manager (TSM) FastBack 5
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2010-3761 [HIGH] CWE-94 GHSA-3frf-gw23-35mh: Unspecified vulnerability in IBM Tivoli Storage Manager (TSM) FastBack 5
Unspecified vulnerability in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-700. NOTE: this might overlap CVE-2010-3058 or CVE-2010-3059.
GHSA
GHSA-8vww-9hj3-5rxx: Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5
ghsa_unreviewed·2022-05-17
CVE-2010-3059 [HIGH] CWE-119 GHSA-8vww-9hj3-5rxx: Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5
Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to read and modify data, and possibly have other impact, via an unspecified command.
GHSA
GHSA-j3q3-5985-p58m: The FXCLI_OraBR_Exec_Command function in FastBackServer
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2010-3754 [HIGH] CWE-78 GHSA-j3q3-5985-p58m: The FXCLI_OraBR_Exec_Command function in FastBackServer
The FXCLI_OraBR_Exec_Command function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 uses values of packet fields to determine the content and length of data copied to memory, which allows remote attackers to execute arbitrary code via a crafted packet. NOTE: this might overlap CVE-2010-3059.
GHSA
GHSA-5mvg-7mqq-mfx7: Multiple stack-based buffer overflows in FastBackServer
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2010-3758 [HIGH] CWE-94 GHSA-5mvg-7mqq-mfx7: Multiple stack-based buffer overflows in FastBackServer
Multiple stack-based buffer overflows in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allow remote attackers to execute arbitrary code via vectors involving the (1) AGI_SendToLog (aka _SendToLog) function; the (2) group, (3) workgroup, or (4) domain name field to the USER_S_AddADGroup function; the (5) user_path variable to the FXCLI_checkIndexDBLocation function; or (6) the _AGI_S_ActivateLTScriptReply (aka ActivateLTScriptReply) function. NOTE: this might overlap CVE-2010-3059.
GHSA
GHSA-9f8x-24h4-4p65: Format string vulnerability in the _Eventlog function in FastBackServer
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2010-3757 [HIGH] CWE-78 GHSA-9f8x-24h4-4p65: Format string vulnerability in the _Eventlog function in FastBackServer
Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string. NOTE: this might overlap CVE-2010-3059.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/41044http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883http://www-01.ibm.com/support/docview.wss?uid=swg21443820http://www.securityfocus.com/bid/42549http://secunia.com/advisories/41044http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883http://www-01.ibm.com/support/docview.wss?uid=swg21443820http://www.securityfocus.com/bid/42549
2010-08-20
Published