QID 372577

Date Published: 2021-05-27

QID 372577: IBM Spectrum Control (Tivoli Storage Productivity Center) Apache Log4j vulnerability (1488939)

IBM Spectrum Protect provides automated, centrally scheduled, policy-managed backup, archive, and space-management capabilities for file servers.

Apache Log4j could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization of untrusted data in SocketServer. This vulnerability affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center).

Affected Versions:
IBM Spectrum Protect 5.3.0.0 through 5.3.5.0

QID Detection Logic(Authenticated):
It checks for vulnerable version of IBM Spectrum Protect (Tivoli Storage Productivity Center).

On successful exploitation it allows an unauthenticated attacker to cause high confidentiality and integrity impact.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released updated version to address this issue. Refer to ibm1488939 for details.
    Vendor References

    CVEs related to QID 372577

    Software Advisories
    Advisory ID Software Component Link
    swg21320822 URL Logo www.ibm.com/support/pages/node/1488939