APP: IBM Tivoli Storage Manager Client CAD Service Buffer Overflow

A buffer overflow vulnerability exists in IBM Tivoli Storage Manager Client software. The vulnerability is due to a boundary error in the Client Acceptor Daemon (CAD) service while processing a specially crafted packet. Remote unauthenticated attackers can exploit this vulnerability to inject and execute arbitrary code on the target system. Successful exploitation of this vulnerability would allow for arbitrary code execution with the SYSTEM privileges of the CAD service. If the attack is not successful, the vulnerable service may terminate abnormally due to memory corruption.

Extended Description

IBM Tivoli Storage Manager is prone to multiple buffer-overflow issues and an unauthorized-access issue. Attackers can exploit these issues to cause a denial-of-service condition, to execute arbitrary code, and to read, copy, edit, or delete files on a victim's computer. Other attacks may also be possible.

Affected Products

Ibm tivoli_storage_manager

Short Name
APP:IBM:TIV-SM-CAD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Buffer CAD CVE-2009-3853 Client IBM Manager Overflow Service Storage Tivoli bid:36916
Release Date
10/13/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3608
Port
tcp/1582
False Positive
Unknown
Vendors

Ibm

CVSS Score

9.3

Found a potential security threat?