PT-2016-3635 · Ibm · Ibm Spectrum Protect
Carlo Beccaria
·
Published
2016-01-20
·
Updated
2016-12-07
·
CVE-2015-4951
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect versions 5.5 through 6.3.2.4
IBM Spectrum Protect versions 6.4 through 6.4.3.0
IBM Spectrum Protect versions 7.1 through 7.1.3
Description
The issue allows remote attackers to cause a denial of service, resulting in a daemon crash, via a crafted Web client URL.
Recommendations
For IBM Spectrum Protect versions 5.5 through 6.3.2.4, update to version 6.3.2.5 or later.
For IBM Spectrum Protect versions 6.4 through 6.4.3.0, update to version 6.4.3.1 or later.
For IBM Spectrum Protect versions 7.1 through 7.1.3, update to version 7.1.3 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Protect