First published: Fri Oct 06 2023(Updated: )
IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Storage Protect Client | <=8.1.0.0 - 8.1.19.0 | |
IBM Storage Protect for Virtual Environments: Data Protection for Hyper-V | <=8.1.0.0 - 8.1.19.0 | |
IBM Storage Protect for Virtual Environments: Data Protection for VMware | <=8.1.0.0 - 8.1.19.0 | |
Ibm Storage Protect | >=8.1.0.0<=8.1.19.0 | |
Ibm Storage Protect | >=8.1.0.0<=8.1.19.0 | |
IBM Storage Protect Client | >=8.1.0.0<=8.1.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35897 is a vulnerability in IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 that could allow a local user to execute arbitrary code on the system using a specially crafted file.
The vulnerability occurs due to a DLL hijacking flaw, which can be exploited by a local user.
The severity of CVE-2023-35897 is high with a CVSS score of 8.4.
A local user can exploit the vulnerability by using a specially crafted file to execute arbitrary code on the system.
Yes, IBM has released a fix for the vulnerability. Please refer to the official IBM support page for more details.