QID 376248

Date Published: 2022-01-20

QID 376248: IBM Spectrum Control Multiple Vulnerabilities (6359903,6359899,6359901)

IBM Spectrum Protect provides automated, centrally scheduled, policy-managed backup, archive, and space-management capabilities for file servers.

Affected Versions:
IBM Spectrum Protect 5.3.0.1 to 5.4.0

QID Detection Logic(Authenticated):
It checks for vulnerable version of IBM Spectrum Control version from version.txt under installation path in windows.

An attacker could exploit this vulnerability to corrupt memory and cause a denial of service ,conduct XSS attacks and execute arbitrary code on the system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Vendor has released updated version to address this issue. Refer to , and for details.
    Software Advisories
    Advisory ID Software Component Link
    6359899 URL Logo www.ibm.com/support/pages/node/6359899
    6359901 URL Logo www.ibm.com/support/pages/node/6359901
    6359903 URL Logo www.ibm.com/support/pages/node/6359903