QID 375925
Date Published: 2021-10-04
QID 375925: IBM Spectrum Protect Server Multiple Vulnerabilities (6446749)
IBM Spectrum Protect provides automated, centrally scheduled, policy-managed backup, archive, and space-management capabilities for file servers.
CVE-2020-4701: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.
CVE-2020-4739: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client.
Affected Versions:
IBM Spectrum Protect Server 8.1.0.000 - 8.1.11.xxx
IBM Spectrum Protect Server 7.1.0.000 - 7.1.12.xxx
QID Detection Logic(Authenticated):
This checks for vulnerable versions of IBM Spectrum Protect.
Successful exploitation it allows an unauthenticated attacker to cause high confidentiality, integrity and availability impact.
- 6446749 -
www.ibm.com/support/pages/node/6446749
CVEs related to QID 375925
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6446749 |
|