Stack-based Buffer Overflows in IBM Tivoli Storage Manager Remote Agent Service
CVE-2008-4828

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
5 May 2009

Summary

The IBM Tivoli Storage Manager (TSM) client suffers from multiple stack-based buffer overflows in dsmagent.exe within the Remote Agent Service. These vulnerabilities can be leveraged by remote attackers to execute arbitrary code. The overflow can be triggered through a malformed request packet that is improperly handled by a generic string processing function or by a crafted NodeName in the dicuGetIdentifyRequest packet. This issue is present across a range of versions, impacting both the Web and Java GUI interfaces.

References

EPSS Score

77% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.