Skip to main content

Vendor/product archive

ibm / spectrum_protect CVEs

Beta · best-effort

18 CVEs tagged to ibm / spectrum_protect6 Critical, 4 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2023-27863

Published May 12, 2023

IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20491

Published Apr 16, 2021

IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking during the parsing of commands. By issuing such a command wi…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5017

Published Jan 8, 2021

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended role and permissions. IBM X-Force ID: 193653.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4415

Published Apr 23, 2020

IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker to execute arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4222

Published Feb 24, 2020

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4213

Published Feb 24, 2020

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4212

Published Feb 24, 2020

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4211

Published Feb 24, 2020

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4210

Published Feb 24, 2020

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-4267

Published Jul 22, 2019

The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow execution of arbitrary code on the local system or the application…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4236

Published Jul 22, 2019

A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if the…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4140

Published Jul 2, 2019

IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IBM X-Force ID: 158336.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4093

Published Apr 2, 2019

IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Spectrum Prootect Client Web User Interface on Windows that t…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1