CVE-2015-0119
published 2015-04-06CVE-2015-0119: FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary code by connecting to the Mount port.
PriorityP349high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.65%
83.9th percentile
FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary code by connecting to the Mount port.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tivoli_storage_manager_fastback | <= 6.1.11.0 | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-657g-vhpr-8xv5: FastBack Mount in IBM Tivoli Storage Manager FastBack 6
ghsa_unreviewed·2022-05-17
CVE-2015-0119 [HIGH] CWE-284 GHSA-657g-vhpr-8xv5: FastBack Mount in IBM Tivoli Storage Manager FastBack 6
FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary code by connecting to the Mount port.
Red Hat
perl-XML-LibXML: "expand_entities" option was not preserved under some circumstances
vendor_redhat·2015-04-23·CVSS 5.0
CVE-2015-3451 [MEDIUM] CWE-611 perl-XML-LibXML: "expand_entities" option was not preserved under some circumstances
perl-XML-LibXML: "expand_entities" option was not preserved under some circumstances
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
Statement: This issue affects the versions of perl-XML-LibXML as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Mitigation: This issue only affects programs using this program in forms such as:
$parser = XML::LibXML->new
or
No detection rules found.
No public exploits indexed.
2015-04-06
Published