First published: Wed Jan 20 2016(Updated: )
Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted Web client URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager | =5.5 | |
IBM Tivoli Storage Manager | =6.1 | |
IBM Tivoli Storage Manager | =6.2 | |
IBM Tivoli Storage Manager | =6.3 | |
IBM Tivoli Storage Manager | =6.4 | |
IBM Tivoli Storage Manager | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4951 has a high severity level due to its potential to cause a denial of service through a crafted Web client URL.
To fix CVE-2015-4951, upgrade IBM Spectrum Protect to versions 6.3.2.5 or higher, 6.4.3.1 or higher, or 7.1.3 or higher.
CVE-2015-4951 affects IBM Spectrum Protect versions 5.5, 6.1, 6.2, 6.3 prior to 6.3.2.5, 6.4 prior to 6.4.3.1, and 7.1 prior to 7.1.3.
CVE-2015-4951 is a remote denial of service vulnerability that can crash the Client Acceptor Daemon.
Administrators and users of affected versions of IBM Spectrum Protect may experience service disruptions due to CVE-2015-4951.