{"api_version":"1","generated_at":"2026-07-23T06:04:34+00:00","cve":"CVE-2010-3757","urls":{"html":"https://cve.report/CVE-2010-3757","api":"https://cve.report/api/cve/CVE-2010-3757.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-3757","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-3757"},"summary":{"title":"CVE-2010-3757","description":"Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string.  NOTE: this might overlap CVE-2010-3059.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-10-05 22:00:06","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-78","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/514069/100/0/threaded","name":"http://www.securityfocus.com/archive/1/514069/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ibm.com/support/docview.wss?uid=swg21443820","name":"http://www.ibm.com/support/docview.wss?uid=swg21443820","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security fixes available for IBM Tivoli Storage Manager FastBack","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://zerodayinitiative.com/advisories/ZDI-10-185/","name":"http://zerodayinitiative.com/advisories/ZDI-10-185/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-3757","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-3757","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"3757","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_fastback","cpe6":"5.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3757","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_fastback","cpe6":"5.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3757","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_fastback","cpe6":"5.5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3757","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_fastback","cpe6":"5.5.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3757","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_fastback","cpe6":"5.5.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3757","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_fastback","cpe6":"5.5.4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3757","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_fastback","cpe6":"5.5.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3757","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_fastback","cpe6":"5.5.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3757","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_fastback","cpe6":"6.1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3757","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_fastback","cpe6":"6.1.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T03:18:53.050Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://zerodayinitiative.com/advisories/ZDI-10-185/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ibm.com/support/docview.wss?uid=swg21443820"},{"name":"IC69883","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883"},{"name":"20100929 ZDI-10-185: IBM TSM FastBack Server _Eventlog Format String Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/514069/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-09-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string.  NOTE: this might overlap CVE-2010-3059."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://zerodayinitiative.com/advisories/ZDI-10-185/"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.ibm.com/support/docview.wss?uid=swg21443820"},{"name":"IC69883","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883"},{"name":"20100929 ZDI-10-185: IBM TSM FastBack Server _Eventlog Format String Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/514069/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-3757","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string.  NOTE: this might overlap CVE-2010-3059."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://zerodayinitiative.com/advisories/ZDI-10-185/","refsource":"MISC","url":"http://zerodayinitiative.com/advisories/ZDI-10-185/"},{"name":"http://www.ibm.com/support/docview.wss?uid=swg21443820","refsource":"CONFIRM","url":"http://www.ibm.com/support/docview.wss?uid=swg21443820"},{"name":"IC69883","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883"},{"name":"20100929 ZDI-10-185: IBM TSM FastBack Server _Eventlog Format String Remote Code Execution Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/514069/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-3757","datePublished":"2010-10-05T21:00:00.000Z","dateReserved":"2010-10-05T00:00:00.000Z","dateUpdated":"2024-08-07T03:18:53.050Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-10-05 22:00:06","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-78","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.0:*:*:*:*:*:*:*","matchCriteriaId":"7A482E38-2B78-4064-8682-F7A571D1734C"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.1:*:*:*:*:*:*:*","matchCriteriaId":"840361B9-B3F8-448B-BC7E-065BA4871E46"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.2:*:*:*:*:*:*:*","matchCriteriaId":"8734E08A-716E-4E29-A440-5FB437F7EF46"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"9FF1E98E-B3F5-4348-8D45-B9A8CC916F47"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.3.0:*:*:*:*:*:*:*","matchCriteriaId":"DA49D704-CCC4-48C0-91F9-E6A3A4181FE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.4.0:*:*:*:*:*:*:*","matchCriteriaId":"5D3202AE-CCAB-4120-8F60-B8809C8B192F"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.5.0:*:*:*:*:*:*:*","matchCriteriaId":"43030674-F9E7-483E-8F47-4B5075A480D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.6.0:*:*:*:*:*:*:*","matchCriteriaId":"7B6611E2-9E6A-407A-8649-874E12F12791"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0.0:*:*:*:*:*:*:*","matchCriteriaId":"6C7756DB-DD6D-4A63-9214-131431F809A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0.1:*:*:*:*:*:*:*","matchCriteriaId":"75B7DD63-0696-4D98-BE7F-05D7E953752E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"3757","Ordinal":"1","Title":"CVE-2010-3757","CVE":"CVE-2010-3757","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"3757","Ordinal":"1","NoteData":"Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string.  NOTE: this might overlap CVE-2010-3059.","Type":"Description","Title":"CVE-2010-3757"},{"CveYear":"2010","CveId":"3757","Ordinal":"2","NoteData":"2010-10-05","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"3757","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}