CVE-2008-4563
high · 10Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.
10
CVSS
29.0%
EPSS (exploit prob.)
98th
EPSS percentile
2009-03-11
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows | all versions |
| ibm | tivoli_storage_manager | 5.2 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.4.2.2 |
| ibm | tivoli_storage_manager | 5.4.2.3 |
| ibm | tivoli_storage_manager | 5.4.2.4 |
| ibm | tivoli_storage_manager | 5.4.4.0 |
| ibm | tivoli_storage_manager_express | 5.3 |
| ibm | tivoli_storage_manager_express | 5.3.3.0 |
| ibm | tivoli_storage_manager_express | 5.3.6.4 |
| ibm | tivoli_storage_manager_express | 5.3.7.3 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0192.html
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=775
- http://osvdb.org/52617
- http://secunia.com/advisories/34245
- http://securitytracker.com/id?1021837
- http://www-01.ibm.com/support/docview.wss?uid=swg21377388
- http://www.securityfocus.com/bid/34077
- http://www.vupen.com/english/advisories/2009/0669
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49188
- http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0192.html
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=775
- http://osvdb.org/52617
- http://secunia.com/advisories/34245
- http://securitytracker.com/id?1021837
- http://www-01.ibm.com/support/docview.wss?uid=swg21377388
- http://www.securityfocus.com/bid/34077
- http://www.vupen.com/english/advisories/2009/0669
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49188
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-4563