Short Name |
APP:IBM:TIV-SM-CAD |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
APP |
Keywords |
IBM Tivoli Storage Manager Client CAD Service Buffer Overflow |
Release Date |
2010/10/13 |
Update Number |
1791 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
A buffer overflow vulnerability exists in IBM Tivoli Storage Manager Client software. The vulnerability is due to a boundary error in the Client Acceptor Daemon (CAD) service while processing a specially crafted packet. Remote unauthenticated attackers can exploit this vulnerability to inject and execute arbitrary code on the target system. Successful exploitation of this vulnerability would allow for arbitrary code execution with the SYSTEM privileges of the CAD service. If the attack is not successful, the vulnerable service may terminate abnormally due to memory corruption.
IBM Tivoli Storage Manager is prone to multiple buffer-overflow issues and an unauthorized-access issue. Attackers can exploit these issues to cause a denial-of-service condition, to execute arbitrary code, and to read, copy, edit, or delete files on a victim's computer. Other attacks may also be possible.