The IBM Spectrum Protect (formerly Tivoli Storage Manager) Server is affected by multiple IBM Db2 vulnerabilities such as buffer overflow and loading binaries from an untrusted path. These Db2 vulnerabilities could allow execution of arbitrary code on the system or elevation of user privileges.
CVE(s): CVE-2018-1922, CVE-2018-1923, CVE-2018-1936, CVE-2018-1978, CVE-2018-1980, CVE-2019-4014, CVE-2019-4015, CVE-2019-4016, CVE-2019-4094
Affected product(s) and affected version(s):
These vulnerabilities affects the following IBM Spectrum Protect (formerly Tivoli Storage Manager) Server levels:
- 8.1.0.0 through 8.1.7.xxx
- 7.1.0.0 through 7.1.9.200
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10882974
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152858
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152859
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/153316
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/154069
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/154078
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/155892
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/155893
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/155894
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/158014
The post IBM Security Bulletin: Multiple Db2 vulnerabilities affect the IBM Spectrum Protect Server (CVE-2018-1922, CVE-2018-1923, CVE-2018-1936, CVE-2018-1978, CVE-2018-1980, CVE-2019-4014, CVE-2019-4015, CVE-2019-4016, CVE-2019-4094) appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/2IVyIIW
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.