CVE-2010-3756
Estado: ModificadaMedia (5)—
The _CalcHashValueWithLength function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly validate an unspecified length value, which allows remote attackers to cause a denial of service (daemon crash) by sending data over TCP. NOTE: this might overlap CVE-2010-3060.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.40%
- Percentil entre todas las CVEs puntuadas: 72
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883
- http://www.ibm.com/support/docview.wss?uid=swg21443820
- http://www.securityfocus.com/archive/1/514070/100/0/threaded
- http://zerodayinitiative.com/advisories/ZDI-10-186/
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883
- http://www.ibm.com/support/docview.wss?uid=swg21443820
- http://www.securityfocus.com/archive/1/514070/100/0/threaded
- http://zerodayinitiative.com/advisories/ZDI-10-186/
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-3756",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-10-05T22:00:06.643",
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ibm.com/support/docview.wss?uid=swg21443820",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/514070/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://zerodayinitiative.com/advisories/ZDI-10-186/",
"source": "cve@mitre.org"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ibm.com/support/docview.wss?uid=swg21443820",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/514070/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://zerodayinitiative.com/advisories/ZDI-10-186/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The _CalcHashValueWithLength function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly validate an unspecified length value, which allows remote attackers to cause a denial of service (daemon crash) by sending data over TCP. NOTE: this might overlap CVE-2010-3060."
},
{
"lang": "es",
"value": "La función _CalcHashValueWithLength en FastBackServer.exe en el servidor de IBM Tivoli Storage Manager (TSM) Fastback v5.5.0.0 a v5.5.6.0 y v6.1.0.0 a v6.1.0.1 no valida correctamente la longitud de un valor no especificado, lo que permite a atacantes remotos provocar una denegación de servicio (mediante caída del demonio) enviando datos sobre TCP. NOTA: esto puede superponerse a CVE-2010-3060."
}
],
"lastModified": "2026-06-16T23:23:27.380",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A482E38-2B78-4064-8682-F7A571D1734C"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "840361B9-B3F8-448B-BC7E-065BA4871E46"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8734E08A-716E-4E29-A440-5FB437F7EF46"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FF1E98E-B3F5-4348-8D45-B9A8CC916F47"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA49D704-CCC4-48C0-91F9-E6A3A4181FE0"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D3202AE-CCAB-4120-8F60-B8809C8B192F"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "43030674-F9E7-483E-8F47-4B5075A480D7"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B6611E2-9E6A-407A-8649-874E12F12791"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6C7756DB-DD6D-4A63-9214-131431F809A0"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75B7DD63-0696-4D98-BE7F-05D7E953752E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}