CVE-2010-3059
Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to read and modify data, and possibly have other impact, via an unspecified command.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to read and modify data, and possibly have other impact, via an unspecified command.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- ibm/tivoli storage manager fastback
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/41044Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883
- http://www-01.ibm.com/support/docview.wss?uid=swg21443820Vendor Advisory
- http://www.securityfocus.com/bid/42549
- http://secunia.com/advisories/41044Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883
- http://www-01.ibm.com/support/docview.wss?uid=swg21443820Vendor Advisory
- http://www.securityfocus.com/bid/42549
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.