IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities
BID:42549
Info
IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities
| Bugtraq ID: | 42549 |
| Class: | Unknown |
| CVE: |
CVE-2010-3061 CVE-2010-3058 CVE-2010-3059 CVE-2010-3060 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2010 12:00AM |
| Updated: | Apr 13 2015 09:05PM |
| Credit: | TippingPoint |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities
IBM Tivoli Storage Manager FastBack is prone to multiple remote code-execution and denial-of-service vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code or cause denial-of-service conditions; other attacks are also possible.
IBM Tivoli Storage Manager FastBack versions prior to 5.5.7 or 6.1.1 are affected.
IBM Tivoli Storage Manager FastBack is prone to multiple remote code-execution and denial-of-service vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code or cause denial-of-service conditions; other attacks are also possible.
IBM Tivoli Storage Manager FastBack versions prior to 5.5.7 or 6.1.1 are affected.
Exploit / POC
IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities
References:
References:
- Tivoli Storage Manager FastBack Hompage (IBM)
- ZDI-10-186 - IBM TSM FastBack _CalcHashValueWithLength Remote Denial of Service (Zero Day Initiative)
- ZDI-10-187 - IBM TSM FastBack Server _DAS_ReadBlockReply Remote Denial of Servic (Zero Day Initiative)
- ZDI-10-179: IBM TSM FastBack Mount Service Arbitrary Overwrite Remote Code Execu (ZDI Disclosures
) - ZDI-10-180: IBM TSM FastBack Server _SendToLog Remote Code Execution Vulnerabili (ZDI Disclosures
) - ZDI-10-181: IBM TSM FastBack Server ActivateLTScriptReply Remote Code Execution (ZDI Disclosures
) - ZDI-10-182: IBM TSM FastBack Server FXCLI_OraBR_Exec_Command Remote Code Executi (ZDI Disclosures
) - ZDI-10-183: IBM TSM FastBack Server FXCLI_checkIndexDBLocation Remote Code Execu (ZDI Disclosures
) - ZDI-10-184: IBM TSM FastBack Server USER_S_AddADGroup Remote Code Execution Vuln (ZDI Disclosures
) - ZDI-10-185: IBM TSM FastBack Server _Eventlog Format String Remote Code Executio (ZDI Disclosures
) - ZDI-10-186: IBM TSM FastBack _CalcHashValueWithLength Remote Denial of Service V (ZDI Disclosures
) - ZDI-10-187: IBM TSM FastBack Server _DAS_ReadBlockReply Remote Denial of Service (ZDI Disclosures
) - Security fixes available for IBM Tivoli Storage Manager FastBack (IBM)