Stack-based Buffer Overflow in IBM Spectrum Protect Client Products
CVE-2021-39048

6.2MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
13 December 2021

Summary

IBM Spectrum Protect Client versions 7.1 and 8.1 are susceptible to a stack-based buffer overflow due to inadequate bounds checking. An attacker with local access may exploit this vulnerability, potentially leading to service disruption. Attackers may manipulate the input to execute unauthorized actions, resulting in a denial of service. For more information on mitigation and updates, visit the official IBM support page.

Affected Version(s)

Spectrum Protect 7.1

Spectrum Protect 8.1

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.