New User, Welcome!     Login

Tivoli Storage Manager

ZDI-07-054: IBM Tivoli Storage Manager Express CAD Service Buffer Overflow Vulnerability

ZDI-07-054: IBM Tivoli Storage Manager Express CAD Service Buffer
            Overflow Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-07-054.html
September 24, 2007

-- CVE ID:
CVE-2007-4880

-- Affected Vendor:
IBM

Secunia Research: IBM Tivoli Storage Manager Remote Agent Service Buffer Overflows

====================================================================== 

                     Secunia Research 04/05/2009

 - IBM Tivoli Storage Manager Remote Agent Service Buffer Overflows -

====================================================================== 
Table of Contents

Affected Software....................................................1

Secunia Research: IBM Tivoli Storage Manager Client CAD Service Script Insertion

====================================================================== 

                     Secunia Research 29/10/2007

  - IBM Tivoli Storage Manager Client CAD Service Script Insertion -

====================================================================== 
Table of Contents

Affected Software....................................................1

Secunia Research: IBM Tivoli Storage Manager CAD Service Buffer Overflow

====================================================================== 

                     Secunia Research 04/11/2009

      - IBM Tivoli Storage Manager CAD Service Buffer Overflow -

====================================================================== 
Table of Contents

Affected Software....................................................1

ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow Vulnerability

ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow 
Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-08-001.html


-- CVE ID:
CVE-2008-0247

-- Affected Vendor:
IBM

ZDI-10-179: IBM TSM FastBack Mount Service Arbitrary Overwrite Remote Code Execution Vulnerability

-- Affected Vendors:
IBM

-- Affected Products:
IBM Tivoli Storage Manager

-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 9966. 
For further product information on the TippingPoint IPS, visit:

ZDI-10-185: IBM TSM FastBack Server _Eventlog Format String Remote Code Execution Vulnerability

-- Affected Vendors:
IBM

-- Affected Products:
IBM Tivoli Storage Manager

-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 9965. 
For further product information on the TippingPoint IPS, visit:

Kryptos Logic Advisory: IBM Tivoli Storage Manager (TSM) Local Root

http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca.txt
http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca-exploit.c

==-===-=====-=======-===========-=============-=================

          IBM Tivoli Storage Manager (TSM) Local Root

                Kryptos Logic, December 2010

==-===-=====-=======-===========-=============-=================


ZDI-10-187: IBM TSM FastBack Server _DAS_ReadBlockReply Remote Denial of Service Vulnerability

-- Affected Vendors:
IBM

-- Affected Products:
IBM Tivoli Storage Manager FastBack

-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 9649. 
For further product information on the TippingPoint IPS, visit:

ZDI-10-180: IBM TSM FastBack Server _SendToLog Remote Code Execution Vulnerability

-- Affected Vendors:
IBM

-- Affected Products:
IBM Tivoli Storage Manager FastBack

-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 9706. 
For further product information on the TippingPoint IPS, visit:

ZDI-10-183: IBM TSM FastBack Server FXCLI_checkIndexDBLocation Remote Code Execution Vulnerability

-- Affected Vendors:
IBM

-- Affected Products:
IBM Tivoli Storage Manager FastBack

-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 9489. 
For further product information on the TippingPoint IPS, visit:

ZDI-10-182: IBM TSM FastBack Server FXCLI_OraBR_Exec_Command Remote Code Execution Vulnerabilities

-- Affected Vendors:
IBM

-- Affected Products:
IBM Tivoli Storage Manager FastBack

-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 9488. 
For further product information on the TippingPoint IPS, visit:

ZDI-10-184: IBM TSM FastBack Server USER_S_AddADGroup Remote Code Execution Vulnerability

-- Affected Vendors:
IBM

-- Affected Products:
IBM Tivoli Storage Manager FastBack

-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 9490. 
For further product information on the TippingPoint IPS, visit:

ZDI-10-181: IBM TSM FastBack Server ActivateLTScriptReply Remote Code Execution Vulnerability

-- Affected Vendors:
IBM

-- Affected Products:
IBM Tivoli Storage Manager FastBack

-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 9866. 
For further product information on the TippingPoint IPS, visit:

ZDI-10-186: IBM TSM FastBack _CalcHashValueWithLength Remote Denial of Service Vulnerability

-- Affected Vendors:
IBM

-- Affected Products:
IBM Tivoli Storage Manager FastBack

-- Vulnerability Details:
This vulnerability allows remote attackers to create a denial of service
condition on vulnerable installations of IBM Tivoli FastBack Server.
Authentication is not required to exploit this vulnerability.



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!