vendor:
IBM Tivoli Storage Manager Command Line Administrative Interface
by:
Paolo Stagno aka VoidSec
7.5
CVSS
HIGH
Stack Based Buffer Overflow
CWE
Product Name: IBM Tivoli Storage Manager Command Line Administrative Interface
Affected Version From: 5.2.0.1
Affected Version To: 5.2.0.1
Patch Exists: NO
Related CWE:
CPE: a:ibm:tivoli_storage_manager_command_line_administrative_interface:5.2.0.1
Platforms Tested: Windows 10 Pro v.10.0.19041 Build 19041
IBM Tivoli Storage Manager Command Line Administrative Interface 5.2.0.1 – id’ Field Stack Based Buffer Overflow
This exploit targets a stack based buffer overflow vulnerability in the IBM Tivoli Storage Manager Command Line Administrative Interface version 5.2.0.1. By exploiting this vulnerability, an attacker can execute arbitrary code or crash the application. The vulnerability occurs when the 'id' field is not properly validated, allowing the attacker to overflow the buffer and overwrite the EIP register. This exploit provides a step-by-step usage guide and includes the necessary code to trigger the vulnerability.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the IBM Tivoli Storage Manager Command Line Administrative Interface.