QID 372577
Date Published: 2021-05-27
QID 372577: IBM Spectrum Control (Tivoli Storage Productivity Center) Apache Log4j vulnerability (1488939)
IBM Spectrum Protect provides automated, centrally scheduled, policy-managed backup, archive, and space-management capabilities for file servers.
Apache Log4j could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization of untrusted data in SocketServer. This vulnerability affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center).
Affected Versions:
IBM Spectrum Protect 5.3.0.0 through 5.3.5.0
QID Detection Logic(Authenticated):
It checks for vulnerable version of IBM Spectrum Protect (Tivoli Storage Productivity Center).
On successful exploitation it allows an unauthenticated attacker to cause high confidentiality and integrity impact.
Solution
Vendor has released updated version to address this issue. Refer to ibm1488939 for details.
Vendor References
- ibm1488939 -
www.ibm.com/support/pages/node/1488939
CVEs related to QID 372577
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| swg21320822 |
|