Vulnerabilities > IBM > Tivoli Storage Manager > High

DATE CVE VULNERABILITY TITLE RISK
2021-05-06 CVE-2020-28198 Out-of-bounds Write vulnerability in IBM Tivoli Storage Manager 5.2.0.1
The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow.
local
high complexity
ibm CWE-787
7.0
2018-11-12 CVE-2018-1786 Resource Exhaustion vulnerability in IBM products
IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state.
network
low complexity
ibm CWE-400
7.5
2017-10-05 CVE-2017-1378 Insufficiently Protected Credentials vulnerability in IBM Tivoli Storage Manager
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user.
local
low complexity
ibm CWE-522
7.8
2017-03-07 CVE-2016-8940 Information Exposure vulnerability in IBM Tivoli Storage Manager
IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries.
network
low complexity
ibm CWE-200
8.8
2017-02-24 CVE-2016-8998 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM Tivoli Storage Manager
IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on the server.
network
low complexity
ibm CWE-119
7.2
2017-02-01 CVE-2016-6045 Cross-Site Request Forgery (CSRF) vulnerability in IBM Tivoli Storage Manager
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2017-02-01 CVE-2016-6043 Session Fixation vulnerability in IBM Tivoli Storage Manager
Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.
local
high complexity
ibm CWE-384
7.0
2017-02-01 CVE-2016-5985 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM Tivoli Storage Manager
The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled.
local
low complexity
ibm CWE-119
7.8