CVE-2007-4880
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 75.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 75.94% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- ibm/tivoli storage manager client
- Source
- cve@mitre.org
References
- http://osvdb.org/38161
- http://secunia.com/advisories/26883Vendor Advisory
- http://securityreason.com/securityalert/3184
- http://www-1.ibm.com/support/docview.wss?uid=swg21268775Patch
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC52905&apar=onlyPatch
- http://www.securityfocus.com/archive/1/480492
- http://www.securityfocus.com/bid/25743Patch
- http://www.securitytracker.com/id?1018725
- http://www.vupen.com/english/advisories/2007/3228
- http://www.zerodayinitiative.com/advisories/ZDI-07-054.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36700
- http://osvdb.org/38161
- http://secunia.com/advisories/26883Vendor Advisory
- http://securityreason.com/securityalert/3184
- http://www-1.ibm.com/support/docview.wss?uid=swg21268775Patch
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC52905&apar=onlyPatch
- http://www.securityfocus.com/archive/1/480492
- http://www.securityfocus.com/bid/25743Patch
- http://www.securitytracker.com/id?1018725
- http://www.vupen.com/english/advisories/2007/3228
- http://www.zerodayinitiative.com/advisories/ZDI-07-054.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36700
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.