CVE-2020-28198: Buffer Overflow
UNSUPPORTED WHEN ASSIGNED The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow. Note: the vulnerability can be exploited when it is used in "interactive" mode while, cause of a max number characters limitation, it cannot be exploited in batch or command line usage (e.g. dsmadmc.exe -id=username -password=pwd). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-28198.
What is the severity of CVE-2020-28198?
The severity of CVE-2020-28198 is high.
Which software version is affected by CVE-2020-28198?
IBM Tivoli Storage Manager Version 5 Release 2 (5.2.0.1) is affected by CVE-2020-28198.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-119 and CWE-787.
Are there any references available for CVE-2020-28198?
Yes, there are references available for CVE-2020-28198. You can find them at the following links: [Reference 1](https://github.com/VoidSec/Exploit-Development/blob/master/windows/x86/local/IBM_ITSM_Administrator_Client_v.5.2.0.1/IBM_TSM_v.5.2.0.1_exploit.py), [Reference 2](https://voidsec.com/tivoli-madness/#IBM_Tivoli_Storage_Manager).