QID 375924
Date Published: 2021-10-04
QID 375924: IBM Spectrum Protect Server Multiple Vulnerabilities (6442991)
IBM Spectrum Protect provides automated, centrally scheduled, policy-managed backup, archive, and space-management capabilities for file servers.
CVE-2020-14782: An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
CVE-2020-27221: Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
Affected Versions:
IBM Spectrum Protect Server 8.1.0.000 - 8.1.11.000
IBM Spectrum Protect Server 7.1.0.000 - 7.1.13.100
QID Detection Logic(Authenticated):
This checks for vulnerable versions of IBM Spectrum Protect.
Successful exploitation it allows an unauthenticated attacker to cause high confidentiality, integrity and availability impact.
- 6442991 -
www.ibm.com/support/pages/node/6442991
CVEs related to QID 375924
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6442991 |
|