CVE-2018-1786: High severity ibm spectrum protect vulnerability
Published Nov 12, 2018
·Updated
IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSEWAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.
Affected Software
8 affected components
IBM Spectrum Protect>=8.1.0.0<=8.1.6.0
IBM Tivoli Storage Manager>=7.1<=7.1.8.3
IBM Spectrum Protect Manager For Virtual Environments Data Protection For Vmware Vmware>=8.1.0.0<=8.1.6.0
IBM Tivoli Storage Manager For Virtual Environments Data Protection For Vmware Vmware>=7.1.0<=7.1.8.3
Linux Linux kernel
Microsoft Windows
IBM Spectrum Protect For Virtual Environments Data Protection For Hyper-v>=8.1.0.0<=8.1.6.0
IBM Tivoli Storage Manager For Virtual Environments Data Protection For Hyper-v>=7.1.0<=7.1.8.0
Remediation
Patch Available
Event History
Nov 12, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-1786.
2
What is the severity of CVE-2018-1786?
The severity of CVE-2018-1786 is high, with a severity value of 7.5.
3
Which software versions are affected by CVE-2018-1786?
IBM Spectrum Protect versions 7.1 to 8.1.6.0 and IBM Tivoli Storage Manager versions 7.1 to 7.1.8.3 are affected by CVE-2018-1786.
4
What is the impact of CVE-2018-1786?
CVE-2018-1786 can cause TCP/IP resource leakage and may result in a denial of service.
5
How can I fix CVE-2018-1786?
Apply the necessary patches or updates provided by IBM to resolve CVE-2018-1786.