CVE-2010-3759: Code Injection
FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 writes a certain value to a memory location specified by a UDP packet field, which allows remote attackers to execute arbitrary code via multiple requests. NOTE: this might overlap CVE-2010-3058.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3759?
CVE-2010-3759 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2010-3759?
To fix CVE-2010-3759, upgrade to a patched version of IBM Tivoli Storage Manager FastBack beyond 6.1.0.1.
What are the affected versions of the software for CVE-2010-3759?
The affected versions for CVE-2010-3759 include IBM Tivoli Storage Manager FastBack 5.5.0.0 to 5.5.6.0 and 6.1.0.0 to 6.1.0.1.
What type of attack can exploit CVE-2010-3759?
CVE-2010-3759 can be exploited by remote attackers to execute arbitrary code on the affected system.
Is there a workaround for CVE-2010-3759 if I cannot update?
There are no known workarounds for CVE-2010-3759; updating to a fixed version is the recommended mitigation.