IBM Tivoli Storage Manager Client 6.2.x < 6.2.5.2 / 6.3.x < 6.3.2 / 6.4 < 6.4.1.3 Local Buffer DoS

low Nessus Plugin ID 77528

Synopsis

A client application installed on the remote Windows host is affected by a denial of service vulnerability.

Description

The version of Tivoli Storage Manager Client installed on the remote Windows host is affected by a denial of service vulnerability.

There is an unspecified overflow condition within the Java GUI configuration wizard and the Preferences Editor. This issue allows a local attacker to cause a denial of service with the wizard or editor.

Solution

Upgrade to Tivoli Storage Manager Client 6.2.5.2 / 6.3.2 / 6.4.1.3 or later.

See Also

http://www.nessus.org/u?a24c7101

http://www-01.ibm.com/support/docview.wss?uid=swg21673318

Plugin Details

Severity: Low

ID: 77528

File Name: tivoli_storage_manager_client_6413.nasl

Version: 1.3

Type: local

Agent: windows

Family: Windows

Published: 9/4/2014

Updated: 8/1/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: cpe:/a:ibm:tivoli_storage_manager_client

Required KB Items: installed_sw/Tivoli Storage Manager Client

Exploit Ease: No known exploits are available

Patch Publication Date: 8/26/2014

Vulnerability Publication Date: 8/12/2014

Reference Information

CVE: CVE-2014-0876

BID: 69261