PT-2016-3635 · Ibm · Ibm Spectrum Protect

Carlo Beccaria

·

Published

2016-01-20

·

Updated

2016-12-07

·

CVE-2015-4951

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect versions 5.5 through 6.3.2.4 IBM Spectrum Protect versions 6.4 through 6.4.3.0 IBM Spectrum Protect versions 7.1 through 7.1.3
Description The issue allows remote attackers to cause a denial of service, resulting in a daemon crash, via a crafted Web client URL.
Recommendations For IBM Spectrum Protect versions 5.5 through 6.3.2.4, update to version 6.3.2.5 or later. For IBM Spectrum Protect versions 6.4 through 6.4.3.0, update to version 6.4.3.1 or later. For IBM Spectrum Protect versions 7.1 through 7.1.3, update to version 7.1.3 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-4951

Affected Products

Ibm Spectrum Protect