CVE-2015-4951: Input Validation
Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted Web client URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4951?
CVE-2015-4951 has a high severity level due to its potential to cause a denial of service through a crafted Web client URL.
How do I fix CVE-2015-4951?
To fix CVE-2015-4951, upgrade IBM Spectrum Protect to versions 6.3.2.5 or higher, 6.4.3.1 or higher, or 7.1.3 or higher.
What versions of IBM Spectrum Protect are affected by CVE-2015-4951?
CVE-2015-4951 affects IBM Spectrum Protect versions 5.5, 6.1, 6.2, 6.3 prior to 6.3.2.5, 6.4 prior to 6.4.3.1, and 7.1 prior to 7.1.3.
What type of vulnerability is CVE-2015-4951?
CVE-2015-4951 is a remote denial of service vulnerability that can crash the Client Acceptor Daemon.
Who is impacted by CVE-2015-4951?
Administrators and users of affected versions of IBM Spectrum Protect may experience service disruptions due to CVE-2015-4951.