cbcvebase.

Ibm Spectrum Protect vulnerabilities

34 known vulnerabilities affecting ibm/spectrum_protect.

Total CVEs
34
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH9MEDIUM17

Vulnerabilities

Page 1 of 2
CVE-2020-4211P2CRITICALCVSS 9.8≥ 10.1.0, < 10.1.5v10.1.52020-02-24
CVE-2020-4211 [CRITICAL] CWE-78 CVE-2020-4211: IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022.
nvd
CVE-2020-4210P2CRITICALCVSS 9.8≥ 10.1.0, < 10.1.5v10.1.52020-02-24
CVE-2020-4210 [CRITICAL] CWE-78 CVE-2020-4210: IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175020.
nvd
CVE-2020-4222P2CRITICALCVSS 9.8≥ 10.1.0, < 10.1.5v10.1.52020-02-24
CVE-2020-4222 [CRITICAL] CWE-78 CVE-2020-4222: IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175091.
nvd
CVE-2020-4213P2CRITICALCVSS 9.8≥ 10.1.0, < 10.1.5v10.1.52020-02-24
CVE-2020-4213 [CRITICAL] CWE-78 CVE-2020-4213: IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175024.
nvd
CVE-2020-4212P2CRITICALCVSS 9.8≥ 10.1.0, < 10.1.5v10.1.52020-02-24
CVE-2020-4212 [CRITICAL] CWE-20 CVE-2020-4212: IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175023.
nvd
CVE-2020-4415P2CRITICALCVSS 9.8≥ 7.1.0.0, ≤ 7.1.10.0≥ 8.1.0.0, ≤ 8.1.9.200+4 more2020-04-23
CVE-2020-4415 [CRITICAL] CWE-20 CVE-2020-4415: IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by im IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker to execute arbitrary code on the system with the privileges of an administrator or user associated with the Spectrum Protect server or cause the Spectrum Protect server to crash. IBM X-Force ID
nvd
CVE-2019-4087P2CRITICALCVSS 9.8v7.1v8.12019-07-02
CVE-2019-4087 [CRITICAL] CWE-787 CVE-2019-4087: IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer o IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges. By sending an overly long request, a remote attacker could overflow a buffer and execute arbitrary code on the syste
nvd
CVE-2022-22394P2HIGHCVSS 8.8v8.1.14.1002022-03-21
CVE-2022-22394 [HIGH] CVE-2022-22394: The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrict The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrator or node access to the vulnerable server.
nvd
CVE-2016-8937P3CRITICALCVSS 9.8v7.1v8.12017-10-05
CVE-2016-8937 [CRITICAL] CWE-287 CVE-2016-8937: The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to the TSM server. IBM X-Force ID: 118750.
nvd
CVE-2019-4088P3HIGHCVSS 7.8v7.1v8.12019-07-02
CVE-2019-4088 [HIGH] CVE-2019-4088: IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain ele IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain elevated privileges on the system, caused by loading a specially crafted library loaded by the dsmqsan module. By setting up such a library, a local attacker could exploit this vulnerability to gain root privileges on the vulnerable system. IBM X-Force ID: 157511.
nvd
CVE-2018-1447P3HIGHCVSS 8.1v7.1v8.12018-04-04
CVE-2018-1447 [HIGH] CWE-916 CVE-2018-1447: The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4. The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Prod
nvd
CVE-2018-1785P3HIGHCVSS 7.5v7.1v8.12018-09-26
CVE-2018-1785 [HIGH] CWE-326 CVE-2018-1785: IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographi IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.
nvd
CVE-2018-1545P3HIGHCVSS 7.5v7.1v8.12018-09-26
CVE-2018-1545 [HIGH] CWE-326 CVE-2018-1545: IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographi IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649.
nvd
CVE-2018-1786P3HIGHCVSS 7.5≥ 8.1.0.0, ≤ 8.1.6.0v7.1+1 more2018-11-12
CVE-2018-1786 [HIGH] CWE-400 CVE-2018-1786: IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.
nvd
CVE-2019-4267P3HIGHCVSS 7.8≥ 7.1.0.0, < 7.1.8.6≥ 8.1.0.0, < 8.1.8.0+2 more2019-07-22
CVE-2019-4267 [HIGH] CWE-119 CVE-2019-4267: The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow execution of arbitrary code on the local system or the application to crash. IBM X-Force ID: 160200.
nvd
CVE-2020-4559P3HIGHCVSS 7.5≥ 8.1.0.000, ≤ 8.1.10.000≥ 7.1.0.000, ≤ 7.1.10.000+2 more2020-08-28
CVE-2020-4559 [HIGH] CWE-20 CVE-2020-4559: IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti imprope IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force ID: 183613.
nvd
CVE-2019-4140P4HIGHCVSS 7.1≥ 7.1.0.0, < 7.1.9.300≥ 8.1.0.0, < 8.1.8.0+2 more2019-07-02
CVE-2019-4140 [HIGH] CWE-200 CVE-2019-4140: IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to rep IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IBM X-Force ID: 158336.
nvd
CVE-2018-1853P4MEDIUMCVSS 6.1v7.1v8.12019-04-08
CVE-2018-1853 [MEDIUM] CWE-1021 CVE-2018-1853: IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijac IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 1
nvd
CVE-2017-1301P4MEDIUMCVSS 5.5v7.1v8.12017-10-05
CVE-2017-1301 [MEDIUM] CWE-59 CVE-2017-1301: IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectr IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various files on the system, which could allow the attacker to overwrite arbitrary
nvd
CVE-2019-4129P4MEDIUMCVSS 5.3v7.1v8.12019-07-02
CVE-2019-4129 [MEDIUM] CWE-209 CVE-2019-4129: IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker could exploit this vulnerability to potentially obtain details on the Operations Center architecture. IBM X-Force ID: 158279.
nvd
Ibm Spectrum Protect vulnerabilities | cvebase