QID 375444

Date Published: 2021-05-27

QID 375444: IBM Spectrum Control Node js Vulnerability(6261327)

IBM Spectrum Protect provides automated, centrally scheduled, policy-managed backup, archive, and space-management capabilities for file servers.

Node.js is vulnerable to a denial of service or could allow a remote attacker to bypass security restrictions. These vulnerabilities may affect IBM Spectrum Control. This vulnerability affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center).

Affected Versions:
IBM Spectrum Protect 5.3.1.0 through 5.3.7.0

QID Detection Logic(Authenticated):
It checks for vulnerable version of IBM Spectrum Protect (Tivoli Storage Productivity Center).

On successful exploitation it allows an unauthenticated attacker to cause high confidentiality and integrity impact.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Vendor has released updated version to address this issue. Refer to ibm6261327 for details.
    Software Advisories
    Advisory ID Software Component Link
    6261327 URL Logo www.ibm.com/support/pages/node/6261327