The IBM Tivoli Storage Manger (IBM Spectrum Protect) client is vulnerable to a remote attacker crashing the Client Acceptor Daemon (CAD) by sending a specially crafted URL to access the Tivoli Storage Manager Web client.
CVEID: CVE-2015-4951**
DESCRIPTION:** IBM Tivoli Storage Manager could allow a remote attacker to crash the Client Acceptor Daemon (CAD) by sending a specially crafted URL is used to access TSM Web client. The vulnerability is exploitable only when the CAD service is running and is managing the web client (i.e., MANAGEDSERVICES option either contains WEBCLIENT or is not explicitly set).
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/105042 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
The Tivoli Storage Manager client is affected by the following levels:
Tivoli Storage Manager Client Release
| Fixing VRM Level|**_
Platform_|Link to Fix / Fix Availability Target**
—|—|—|—
7.1| 7.1.3| AIX
HP-UX
Linux
Mac
Solaris
Windows| http://www.ibm.com/support/docview.wss?uid=swg24040368
6.4| 6.4.3.1| AIX
HP-UX
Linux
Mac
Solaris
Windows| http://www.ibm.com/support/docview.wss?uid=swg24041144
6.3| 6.3.2.5| AIX
HP-UX
Linux
Mac
Solaris
Windows| http://www.ibm.com/support/docview.wss?uid=swg24037930
6.2, 6.1, and 5.5|
|
| IBM recommends 6.2, 6.1, and 5.5 users upgrade to a fixed level (7.1.3, 6.4.3.1, or 6.3.2.5 - see links provided above).
None