CVE-2023-35897: IBM Spectrum Protect code execution
IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246.
Other sources
IBM Spectrum Protect Client could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-35897?
CVE-2023-35897 is a vulnerability in IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 that could allow a local user to execute arbitrary code on the system using a specially crafted file.
How does the vulnerability in IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 occur?
The vulnerability occurs due to a DLL hijacking flaw, which can be exploited by a local user.
What is the severity of CVE-2023-35897?
The severity of CVE-2023-35897 is high with a CVSS score of 8.4.
How can a local user exploit the vulnerability in IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0?
A local user can exploit the vulnerability by using a specially crafted file to execute arbitrary code on the system.
Is there a fix available for CVE-2023-35897?
Yes, IBM has released a fix for the vulnerability. Please refer to the official IBM support page for more details.