cbcvebase.

Ibm Tivoli Storage Manager vulnerabilities

49 known vulnerabilities affecting ibm/tivoli_storage_manager.

Total CVEs
49
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH18MEDIUM15LOW9

Vulnerabilities

Page 1 of 3
CVE-2009-3853P2CRITICALCVSS 9.3PoCv5.2.5.3v5.3+22 more2009-11-04
CVE-2009-3853 [CRITICAL] CWE-119 CVE-2009-3853: Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivol Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via crafted data in a TCP packet.
nvd
CVE-2008-4563P3CRITICALCVSS 10.0v5.2v5.3+14 more2009-03-11
CVE-2008-4563 [CRITICAL] CWE-119 CVE-2008-4563: Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the back Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.
nvd
CVE-2010-4604P3HIGHCVSS 7.2PoC≥ 5.3.0, ≤ 5.3.6.7≥ 5.4.0, ≤ 5.4.3.3+2 more2010-12-29
CVE-2010-4604 [HIGH] CWE-787 CVE-2010-4604: Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communicatio Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x before 6.1.3.1 on Unix and Linux allows local users to gain privileges by specifying a long LAN
nvd
CVE-2016-8937P3CRITICALCVSS 9.8v6.1v6.1.0+63 more2017-10-05
CVE-2016-8937 [CRITICAL] CWE-287 CVE-2016-8937: The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to the TSM server. IBM X-Force ID: 118750.
nvd
CVE-2006-5855P3CRITICALCVSS 10.0v5.2.7v5.2.8+4 more2006-12-06
CVE-2006-5855 [CRITICAL] CVE-2006-5855: Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 al Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in (1) the language field at logon that begins with a 0x18 byte, (2) two unspecified parameters to the SmExecuteWdsfSession function, and (3) the c
nvd
CVE-2010-4606P3HIGHCVSS 7.5≥ 5.4.0, < 5.4.3.4≥ 5.5.0, < 5.5.3+2 more2010-12-29
CVE-2010-4606 [HIGH] CVE-2010-4606: Unspecified vulnerability in the Space Management client in the Hierarchical Storage Management (HSM Unspecified vulnerability in the Space Management client in the Hierarchical Storage Management (HSM) component in IBM Tivoli Storage Manager (TSM) 5.4.x before 5.4.3.4, 5.5.x before 5.5.3, 6.1.x before 6.1.4, and 6.2.x before 6.2.2 on Unix and Linux allows remote attackers to execute arbitrary commands via unknown vectors, related to a "script execution vulner
nvd
CVE-2009-3854P3CRITICALCVSS 10.0v5.2.5.3v5.3+16 more2009-11-04
CVE-2009-3854 [CRITICAL] CWE-119 CVE-2009-3854: Buffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM Buffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7 and 5.4 before 5.4.2 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-8940P3HIGHCVSS 8.8v6.1v6.1.0+48 more2017-03-07
CVE-2016-8940 [HIGH] CWE-200 CVE-2016-8940: IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific database tables may allow access to pass
nvd
CVE-2016-8998P3HIGHCVSS 7.2v7.1.1v7.1.1.1+15 more2017-02-24
CVE-2016-8998 [HIGH] CWE-119 CVE-2016-8998: IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privi IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on the server. IBM Reference #: 1998747.
nvd
CVE-2009-3855P3CRITICALCVSS 9.3v5.2.5.3v5.3+15 more2009-11-04
CVE-2009-3855 [CRITICAL] CVE-2009-3855: Multiple unspecified vulnerabilities in the (1) UNIX and (2) Linux backup-archive clients, and the ( Multiple unspecified vulnerabilities in the (1) UNIX and (2) Linux backup-archive clients, and the (3) OS/400 API client, in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.6, 5.4 before 5.4.2, and 5.5 before 5.5.1, when the MAILPROG option is enabled, allow attackers to read, modify, or delete arbitrary files via unknown vectors.
nvd
CVE-2009-1178P3CRITICALCVSS 10.0v5.3.0v5.3.1+1 more2009-03-31
CVE-2009-1178 [CRITICAL] CVE-2009-1178: Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6 Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vectors related to the "admin command line."
nvd
CVE-2016-6045P3HIGHCVSS 8.8v6.4.1v6.4.1.1+17 more2017-02-01
CVE-2016-6045 [HIGH] CWE-352 CVE-2016-6045: IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2016-5985P3HIGHCVSS 7.8≤ 7.1.6.2v7.1.0.0+7 more2017-02-01
CVE-2016-5985 [HIGH] CWE-119 CVE-2016-5985: The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer and execute arbitrary code on the system or cause a system crash.
nvd
CVE-2018-1786P3HIGHCVSS 7.5≥ 7.1, ≤ 7.1.8.32018-11-12
CVE-2018-1786 [HIGH] CWE-400 CVE-2018-1786: IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.
nvd
CVE-2017-1378P4HIGHCVSS 7.8v6.1v6.1.0+60 more2017-10-05
CVE-2017-1378 [HIGH] CWE-522 CVE-2017-1378: IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login crede IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.
nvd
CVE-2014-6184P4HIGHCVSS 7.2≥ 5.4.0, ≤ 5.4.3.6≥ 5.5.0, ≤ 5.5.4.3+3 more2015-02-22
CVE-2014-6184 [HIGH] CWE-787 CVE-2014-6184: Stack-based buffer overflow in dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4 through Stack-based buffer overflow in dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4 through 5.4.3.6, 5.5 through 5.5.4.3, 6.1 through 6.1.5.6, 6.2 before 6.2.5.4, and 6.3 before 6.3.2.3 on UNIX, Linux, and OS X allows local users to gain privileges via unspecified vectors.
nvd
CVE-2020-28198P4HIGHCVSS 7.0v5.2.0.12021-05-06
CVE-2020-28198 [HIGH] CWE-787 CVE-2020-28198: The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative In The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow. Note: the vulnerability can be exploited when it is used in "interactive" mode while, cause of a max number characters limitation, it cannot be exploited in batch or command li
nvd
CVE-2002-0541P4HIGHCVSS 7.5v4.2v4.2.12002-07-03
CVE-2002-0541 [HIGH] CVE-2002-0541: Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 1580 or port 1581.
nvd
CVE-2014-6185P4HIGHCVSS 7.2v6.3.0v6.3.0.5+20 more2015-02-13
CVE-2014-6185 [HIGH] CWE-264 CVE-2014-6185: dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict shared-library loading, which allows local users to gain privileges via a crafted DSO file.
nvd
CVE-2013-2964P4HIGHCVSS 7.2v6.3.0v6.3.0.17+62 more2013-10-04
CVE-2013-2964 [HIGH] CWE-119 CVE-2013-2964: Buffer overflow in dsmtca in IBM Tivoli Storage Manager (TSM) through 5.5.4.0, 6.1.0 through 6.1.5.4 Buffer overflow in dsmtca in IBM Tivoli Storage Manager (TSM) through 5.5.4.0, 6.1.0 through 6.1.5.4, 6.2.0 through 6.2.4.7, and 6.3.0 through 6.3.0.17 on UNIX and Linux allows local users to gain privileges via unspecified vectors.
nvd
Ibm Tivoli Storage Manager vulnerabilities | cvebase