First published: Wed Feb 01 2017(Updated: )
The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer and execute arbitrary code on the system or cause a system crash.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager | <=7.1.6.2 | |
IBM Tivoli Storage Manager | =7.1.0.0 | |
IBM AIX | ||
IBM Tivoli Storage Manager | <=6.4.3.3 | |
IBM Tivoli Storage Manager | =6.4.0.0 | |
IBM Tivoli Storage Manager | <=6.3.2.5 | |
IBM Tivoli Storage Manager | =6.3.0.0 | |
IBM Tivoli Storage Manager | <=6.1 | |
IBM Tivoli Storage Manager | <=6.2 | |
IBM Tivoli Storage Manager | <=5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5985 has a high severity rating due to the potential for local attackers to execute arbitrary code or crash the system.
To fix CVE-2016-5985, users should upgrade to a version of IBM Tivoli Storage Manager that is not vulnerable, specifically above version 7.1.6.2 or 6.4.3.3.
CVE-2016-5985 affects IBM Tivoli Storage Manager versions up to 7.1.6.2 and 6.4.3.3.
CVE-2016-5985 allows for local buffer overflow attacks, enabling execution of arbitrary code.
Yes, CVE-2016-5985 specifically impacts the IBM Tivoli Storage Manager AIX client.