| Vulnerability Name: | CVE-2010-3058 (CCN-61215) | ||||||||
| Assigned: | 2010-08-18 | ||||||||
| Published: | 2010-08-18 | ||||||||
| Updated: | 2010-08-24 | ||||||||
| Summary: | The Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, establishes an open UDP port, which might allow remote attackers to overwrite memory locations and execute arbitrary code, or cause a denial of service (application hang), via unspecified vectors. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-399 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2010-3058 Source: CCN Type: SA41044 IBM Tivoli Storage Manager FastBack Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 41044 Source: AIXAPAR Type: UNKNOWN IC69883 Source: CCN Type: IBM Software and Downloads Security fixes available for IBM Tivoli Storage Manager FastBack Source: CONFIRM Type: UNKNOWN http://www-01.ibm.com/support/docview.wss?uid=swg21443820 Source: CCN Type: OSVDB ID: 67292 IBM Tivoli Storage Manager (TSM) FastBack Mount Service Unspecified Memory Corruption Source: CCN Type: OSVDB ID: 68399 IBM Tivoli Storage Manager (TSM) FastBack Mount Service FastBackMount.exe UDP Packet Field Multiple Request Arbitrary Code Execution Source: CCN Type: OSVDB ID: 68400 IBM Tivoli Storage Manager (TSM) FastBack Unspecified Arbitrary Code Execution Source: BID Type: UNKNOWN 42549 Source: CCN Type: BID-42549 IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities Source: XF Type: UNKNOWN tivoli-storage-mount-code-exec(61215) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||