IBM.Tivoli.Storage.Manager.Requests.Handling.Buffer.Overflow

description-logoDescription

This indicates an attempt to exploit a buffer overflow vulnerability in IBM Tivoli Storage Manager.
The vulnerability is caused by an error that occurs when the vulnerable software handles initial sign-on request network messages. It allows a remote attacker to execute arbitrary code via initial sign-on request network messages.
A remote unauthenticated attacker may exploit this flaw to cause denial of service, or inject and execute arbitrary code on the target host, normally with System privileges.

affected-products-logoAffected Products

IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4

Impact logoImpact

Denial of service.
System compromise.

recomended-action-logoRecommended Actions

Apply APAR IC50347, available from the IBM Support & downloads Web site.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)