IBM Spectrum Protect (formerly Tivoli Storage Manager) Server is affected by multiple IBM DB2 vulnerabilities that could allow a local user to overwrite DB2 files, cause a denial of service, or allow a local attacker to execute arbitrary code on the system.
CVEID: CVE-2017-1105**
DESCRIPTION:** IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668
CVSS Base Score: 5.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/120668 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
CVEID: CVE-2017-1297**
DESCRIPTION:** IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/125159 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
This vulnerability affects the following IBM Spectrum Protect (formerly Tivoli Storage Manager) server levels:
Platform_|Link to Fix / Fix Availability Target**
—|—|—|—
8.1| 8.1.3| AIX
Linux
Windows| <ftp://public.dhe.ibm.com/storage/tivoli-storage-management/maintenance/server/v8r1/>
7.1| 7.1.8| AIX
HP-UX
Linux
Solaris
Windows| <ftp://public.dhe.ibm.com/storage/tivoli-storage-management/maintenance/server/v7r1/>
6.3 and below|
|
| 6.3 and below are EOS. Customers on these releases can upgrade the server to a fixed level (8.1.3 or 7.1.8).
Note that 6.4 shipped with 6.3 servers.
None