Vulnerabilities > IBM > Spectrum Protect > 8.1.7

DATE CVE VULNERABILITY TITLE RISK
2020-08-28 CVE-2020-4559 Improper Input Validation vulnerability in IBM Spectrum Protect
IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input.
network
low complexity
ibm CWE-20
5.0
2020-04-23 CVE-2020-4415 Out-of-bounds Write vulnerability in IBM Spectrum Protect
IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking.
network
low complexity
ibm CWE-787
critical
10.0
2019-11-25 CVE-2018-2025 Incorrect Default Permissions vulnerability in IBM products
IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone.
local
low complexity
ibm CWE-276
3.6
2019-07-22 CVE-2019-4267 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM Spectrum Protect
The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow.
local
low complexity
ibm CWE-119
7.8
2019-07-02 CVE-2019-4140 Information Exposure vulnerability in IBM Spectrum Protect
IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data.
local
low complexity
ibm CWE-200
7.1
2019-04-02 CVE-2019-4093 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Spectrum Protect 8.1.7
IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Spectrum Prootect Client Web User Interface on Windows that they should not have access to due to incorrect file permissions.
local
low complexity
ibm microsoft CWE-732
3.6