PT-2021-18397 · Ibm · Ibm Spectrum Protect Client

Published

2021-04-26

·

Updated

2022-09-30

·

CVE-2021-29672

CVSS v3.1

8.4

High

VectorAC:L/C:H/PR:N/AV:L/UI:N/I:H/S:U/A:H
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect Client versions 8.1.0.0-8 through 1.11.0
Description The issue is caused by improper bounds checking when processing the current locale settings, leading to a stack-based buffer overflow. A local attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges or cause the application to crash.
Recommendations For IBM Spectrum Protect Client versions 8.1.0.0-8 through 1.11.0, update to a version that includes the fix for the improper bounds checking issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29672

Affected Products

Ibm Spectrum Protect Client