CVE-2010-3756
The _CalcHashValueWithLength function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly validate an unspecified length value, which allows remote…
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
The _CalcHashValueWithLength function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly validate an unspecified length value, which allows remote attackers to cause a denial of service (daemon crash) by sending data over TCP. NOTE: this might overlap CVE-2010-3060.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- ibm/tivoli storage manager fastback
- Source
- cve@mitre.org
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21443820
- http://www.securityfocus.com/archive/1/514070/100/0/threaded
- http://zerodayinitiative.com/advisories/ZDI-10-186/
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21443820
- http://www.securityfocus.com/archive/1/514070/100/0/threaded
- http://zerodayinitiative.com/advisories/ZDI-10-186/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.