Vulnerability Name: | CVE-2010-3059 (CCN-61217) | ||||||||
Assigned: | 2010-08-18 | ||||||||
Published: | 2010-08-18 | ||||||||
Updated: | 2010-08-23 | ||||||||
Summary: | Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to read and modify data, and possibly have other impact, via an unspecified command. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-3059 Source: CCN Type: SA41044 IBM Tivoli Storage Manager FastBack Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 41044 Source: AIXAPAR Type: UNKNOWN IC69883 Source: CCN Type: IBM Software and Downloads Security fixes available for IBM Tivoli Storage Manager FastBack Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21443820 Source: CCN Type: OSVDB ID: 67291 IBM Tivoli Storage Manager (TSM) FastBack Server Client Message Handling Overflow Source: CCN Type: OSVDB ID: 68394 IBM Tivoli Storage Manager (TSM) FastBack Server FastBackServer.exe FXCLI_OraBR_Exec_Command Function Arbitrary Code Execution Source: CCN Type: OSVDB ID: 68397 IBM Tivoli Storage Manager (TSM) FastBack Server FastBackServer.exe _Eventlog Function Format String Arbitrary Code Execution Source: CCN Type: OSVDB ID: 68398 IBM Tivoli Storage Manager (TSM) FastBack Server FastBackServer.exe Multiple Function Overflows Source: BID Type: UNKNOWN 42549 Source: CCN Type: BID-42549 IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities Source: XF Type: UNKNOWN tivoli-storage-fastback-bo(61217) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |