
CVE-2023-28956 – IBM Spectrum Protect Backup-Archive Client privilege escalation
https://notcve.org/view.php?id=CVE-2023-28956
22 Jun 2023 — IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. IBM X-Force ID: 251767. IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. • https://exchange.xforce.ibmcloud.com/vulnerabilities/251767 • CWE-266: Incorrect Privilege Assignment •

CVE-2021-39048 – Gentoo Linux Security Advisory 202209-02
https://notcve.org/view.php?id=CVE-2021-39048
13 Dec 2021 — IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438. IBM Spectrum Protect Client versiones 7.1 y 8.1, es vulnerable a un desbordamiento del búfer en la región stack de la memoria, causado por una comprobación inapropiada de límites. Un atacante local podría aprovechar esta vulnerabilidad y causar una denegación de servicio. • https://exchange.xforce.ibmcloud.com/vulnerabilities/214438 • CWE-787: Out-of-bounds Write •

CVE-2021-20532
https://notcve.org/view.php?id=CVE-2021-20532
26 Apr 2021 — IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811. IBM Spectrum Protect Client versiones 8.1.0.0 hasta 8.1.11.0, podría permitir a un usuario local escalar sus privilegios para tomar el control total del sistema debido a permisos de directorio no seguros. IBM X-Force ID: 198811 • https://exchange.xforce.ibmcloud.com/vulnerabilities/198811 • CWE-276: Incorrect Default Permissions •

CVE-2019-4406
https://notcve.org/view.php?id=CVE-2019-4406
25 Nov 2019 — IBM Spectrum Protect Backup-Archive Client 7.1 and 8.1 may be vulnerable to a denial of service attack due to a timing issue between client and server TCP/IP communications. IBM X-Force ID: 162477. IBM Spectrum Protect Backup-Archive Client versiones 7.1 y 8.1, pueden ser vulnerables a un ataque de denegación de servicio debido a un problema de sincronización entre las comunicaciones TCP/IP del cliente y el servidor. ID de IBM X-Force: 162477. • https://exchange.xforce.ibmcloud.com/vulnerabilities/162477 •

CVE-2018-1882
https://notcve.org/view.php?id=CVE-2018-1882
08 Apr 2019 — In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968. En ciertas configuraciones atípicas de IBM Spectrum Protect versiones 7.1 y 8.1, la contraseña del nodo podría mostrarse en texto plano en el archivo de rastreo del cliente de IBM Spectrum Protect. ID de IBM X-Force: 151968. • http://www.ibm.com/support/docview.wss?uid=ibm10869208 • CWE-312: Cleartext Storage of Sensitive Information •

CVE-2018-1853
https://notcve.org/view.php?id=CVE-2018-1853
08 Apr 2019 — IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 151014. IBM Tivoli Storage Manager (IBM Spectrum Protect versiones 7.1 y 8.1), podría permitir a un atacante remoto secuestrar la acción de cliqueo de la víctima... • http://www.ibm.com/support/docview.wss?uid=ibm10870718 • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •

CVE-2018-1787
https://notcve.org/view.php?id=CVE-2018-1787
08 Apr 2019 — IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872. IBM Spectrum Protect versiones 7.1 y 8.1, se ve afectado por una vulnerabilidad de exposición de contraseña causada por permisos de archivos no seguros. ID de IBM X-Force: 148872. • http://www.ibm.com/support/docview.wss?uid=ibm10869602 • CWE-732: Incorrect Permission Assignment for Critical Resource •