PT-2019-2561 · Ibm · Ibm Spectrum Protect Server+1
Published
2019-07-02
·
Updated
2022-12-09
·
CVE-2019-4087
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect Servers versions 7.1 through 8.1
IBM Spectrum Protect Storage Agents versions 7.1 through 8.1
Description
The issue is related to a stack-based buffer overflow caused by improper bounds checking in response to specifically crafted communication exchanges. A remote attacker could overflow a buffer by sending an overly long request, potentially executing arbitrary code on the system with instance id privileges or causing the server or storage agent to crash.
Recommendations
For IBM Spectrum Protect Servers versions 7.1 through 8.1, update to a version that includes the fix for the buffer overflow issue.
For IBM Spectrum Protect Storage Agents versions 7.1 through 8.1, update to a version that includes the fix for the buffer overflow issue.
As a temporary workaround, consider restricting access to the servers and storage agents to minimize the risk of exploitation.
Fix
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Spectrum Protect Server
Ibm Spectrum Protect Storage Agents