CVE-2021-39048

Severity
5.5MEDIUM
EPSS
0.1%
top 80.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateDec 14

Description

IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDibm/spectrum_protect_backup-archive_client8.1.0.08.1.12.0+1
NVDibm/spectrum_protect8.1.0.08.1.12.0+1
CVEListV5ibm/spectrum_protect7.1, 8.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4h4x-cgp7-h27m: IBM Spectrum Protect Client 72021-12-14
CVEList
CVE-2021-39048: IBM Spectrum Protect Client 72021-12-13
CVE-2021-39048 (MEDIUM CVSS 5.5) | IBM Spectrum Protect Client 7.1 and | cvebase.io