Lucene search

K
ibmIBM90A1A901492A59B1FF101783149AE028867C70343D6F81A1286FA85C6DD9F086
HistoryAug 19, 2022 - 9:04 p.m.

Security Bulletin: IBM Tivoli Storage Manager FastBack Stack-Based Buffer Overflow Vulnerability (CVE-2015-1929)

2022-08-1921:04:31
www.ibm.com
9
ibm tivoli storage manager
fastback
stack-based buffer overflow
cve-2015-1929
remote attacker
server crash
6.1.11.1
security fix
vulnerability
network attacker
ibm
tivoli
storage manager.

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.932

Percentile

99.1%

Summary

The IBM Tivoli Storage Manager FastBack Server process is vulnerable to a stack-based buffer overflow. A network attacker could overflow a buffer and cause the server to crash.

Vulnerability Details

CVEID: CVE-2015-1929**
DESCRIPTION:** IBM Tivoli Storage Manager FastBack Server is vulnerable to a stack based buffer overflow, which would allow a remote attacker to cause the server to crash.
CVSS Base Score: 7.8
CVSS Temporal Score: See _<https://exchange.xforce.ibmcloud.com/vulnerabilities/102965&gt;_ for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C)

Affected Products and Versions

IBM Tivoli Storage Manager FastBack Mount 6.1.11.1 and earlier

Remediation/Fixes

_FastBack Release _

| First FixingVRMF Level| Platfom| APAR| Link to fix
—|—|—|—|—
6.1 | 6.1.12| Windows| None| <http://www-933.ibm.com/support/fixcentral/swg/selectFix?product=ibm%2FTivoli%2FIBM+Tivoli+Storage+Manager+FastBack&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmtivoli_storage_manager_fastbackMatch6.1
OR
ibmtivoli_storage_manager_fastbackMatch6.1.1
OR
ibmtivoli_storage_manager_fastbackMatch6.1.2
OR
ibmtivoli_storage_manager_fastbackMatch6.1.3
OR
ibmtivoli_storage_manager_fastbackMatch6.1.4
OR
ibmtivoli_storage_manager_fastbackMatch6.1.5
OR
ibmtivoli_storage_manager_fastbackMatch6.1.6
OR
ibmtivoli_storage_manager_fastbackMatch6.1.7
OR
ibmtivoli_storage_manager_fastbackMatch6.1.8
OR
ibmtivoli_storage_manager_fastbackMatch6.1.9
OR
ibmtivoli_storage_manager_fastbackMatch6.1.10
OR
ibmtivoli_storage_manager_fastbackMatch6.1.11
VendorProductVersionCPE
ibmtivoli_storage_manager_fastback6.1cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1:*:*:*:*:*:*:*
ibmtivoli_storage_manager_fastback6.1.1cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.1:*:*:*:*:*:*:*
ibmtivoli_storage_manager_fastback6.1.2cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.2:*:*:*:*:*:*:*
ibmtivoli_storage_manager_fastback6.1.3cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.3:*:*:*:*:*:*:*
ibmtivoli_storage_manager_fastback6.1.4cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.4:*:*:*:*:*:*:*
ibmtivoli_storage_manager_fastback6.1.5cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.5:*:*:*:*:*:*:*
ibmtivoli_storage_manager_fastback6.1.6cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6:*:*:*:*:*:*:*
ibmtivoli_storage_manager_fastback6.1.7cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7:*:*:*:*:*:*:*
ibmtivoli_storage_manager_fastback6.1.8cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.8:*:*:*:*:*:*:*
ibmtivoli_storage_manager_fastback6.1.9cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.932

Percentile

99.1%

Related for 90A1A901492A59B1FF101783149AE028867C70343D6F81A1286FA85C6DD9F086