Vulnerability Name: | CVE-2008-4828 (CCN-50327) | ||||||||
Assigned: | 2008-10-31 | ||||||||
Published: | 2009-04-05 | ||||||||
Updated: | 2018-10-11 | ||||||||
Summary: | Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 8.3 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
8.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-4828 Source: OSVDB Type: UNKNOWN 54231 Source: OSVDB Type: UNKNOWN 54232 Source: CCN Type: SA32604 IBM Tivoli Storage Manager Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 32604 Source: CCN Type: Secunia Research 04/05/2009 IBM Tivoli Storage Manager Remote Agent Service Buffer Overflows Source: MISC Type: Vendor Advisory http://secunia.com/secunia_research/2008-55/ Source: CCN Type: IBM Support & downloads Security fixes for the IBM Tivoli Storage Manager (TSM) client Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21384389 Source: AIXAPAR Type: Patch, Vendor Advisory IC59513 Source: CCN Type: OSVDB ID: 54231 IBM Tivoli Storage Manager (TSM) Agent Client (dsmagent.exe) Request Packet String Handling Overflow Source: CCN Type: OSVDB ID: 54232 IBM Tivoli Storage Manager (TSM) Agent Client (dsmagent.exe) dicuGetIdentifyRequest Request Packet NodeName Overflow Source: BUGTRAQ Type: UNKNOWN 20090504 Secunia Research: IBM Tivoli Storage Manager Remote Agent Service Buffer Overflows Source: CCN Type: BID-34803 IBM Tivoli Storage Manager Multiple Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2009-1235 Source: XF Type: UNKNOWN ibm-tsm-dsmagent-bo(50327) Source: XF Type: UNKNOWN ibm-tsm-dsmagent-bo(50327) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |