QID 375635
Date Published: 2021-06-21
QID 375635: IBM Spectrum Protect Server Multiple Vulnerabilities (6462189)
IBM Spectrum Protect provides automated, centrally scheduled, policy-managed backup, archive, and space-management capabilities for file servers.
CVE-2020-5024 - IBM DB2 Windows could allow an unauthenticated attacker to cause a denial of service due a hang in the SSL handshake response.
CVE-2020-5025 - IBM DB2 for Windows is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.
CVE-2020-4976 - IBM DB2 for Windows could allow a local user to read and write specific files due to weak file permissions.
Affected Versions:
IBM Spectrum Protect Server.1.0.000 - 8.1.12.000
IBM Spectrum Protect Server 7.1.0.000 - 7.1.13.100
QID Detection Logic(Authenticated):
This checks for vulnerable versions of IBM Spectrum Protect.
On successful exploitation it allows an unauthenticated attacker to cause high confidentiality and integrity impact.
- 6462189 -
www.ibm.com/support/pages/node/6462189
CVEs related to QID 375635
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6462189 |
|