PT-2021-11457 · Ibm · Ibm Tivoli Storage Manager
Voidsec
·
Published
2021-05-06
·
Updated
2024-08-04
·
CVE-2020-28198
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
IBM Tivoli Storage Manager Version 5 Release 2
Description:
The issue concerns a stack buffer overflow that can be exploited through the
id parameter when used in interactive mode. This exploitation is limited by a maximum number of characters and cannot be exploited in batch or command line usage, such as through commands like dsmadmc.exe -id=username -password=pwd. It's noted that this vulnerability affects products that are no longer supported by the maintainer.Recommendations:
For IBM Tivoli Storage Manager Version 5 Release 2, as a temporary workaround, consider restricting the use of the
id parameter in interactive mode to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Tivoli Storage Manager