Saturday, June 29, 2019

IBM Security Bulletin: Multiple Db2 vulnerabilities affect the IBM Spectrum Protect Server (CVE-2018-1922, CVE-2018-1923, CVE-2018-1936, CVE-2018-1978, CVE-2018-1980, CVE-2019-4014, CVE-2019-4015, CVE-2019-4016, CVE-2019-4094)

The IBM Spectrum Protect (formerly Tivoli Storage Manager) Server is affected by multiple IBM Db2 vulnerabilities such as buffer overflow and loading binaries from an untrusted path. These Db2 vulnerabilities could allow execution of arbitrary code on the system or elevation of user privileges.

CVE(s): CVE-2018-1922, CVE-2018-1923, CVE-2018-1936, CVE-2018-1978, CVE-2018-1980, CVE-2019-4014, CVE-2019-4015, CVE-2019-4016, CVE-2019-4094

Affected product(s) and affected version(s):

These vulnerabilities affects the following IBM Spectrum Protect (formerly Tivoli Storage Manager) Server levels:

  • 8.1.0.0 through 8.1.7.xxx
  • 7.1.0.0 through 7.1.9.200

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10882974
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152858
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152859
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/153316
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/154069
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/154078
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/155892
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/155893
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/155894
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/158014

The post IBM Security Bulletin: Multiple Db2 vulnerabilities affect the IBM Spectrum Protect Server (CVE-2018-1922, CVE-2018-1923, CVE-2018-1936, CVE-2018-1978, CVE-2018-1980, CVE-2019-4014, CVE-2019-4015, CVE-2019-4016, CVE-2019-4094) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2IVyIIW

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.