CVE-2019-4087
IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges. By sending an overly long request, a remote attacker could overflow a buffer and execute arbitrary code on the system with instance id privileges or cause the server or storage agent to crash. IBM X-Force ID: 157510.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.96% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- ibm/spectrum protect operations center
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=ibm10882472Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/157510VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10882472Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/157510VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.