Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

123 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.41%—IBM Tivoli Storage Manager6/5/202117/6/2026
The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow. Note: the vulnerability can be exploited when it is used in "interactive" mode while, cause of a max number characters limitation, it cannot…
ModificadaAlta (7.5)2.4%—IBM Spectrum ProtectIBM Tivoli Storage ManagerIBM Spectrum Protect Manager FOR Virtual Environments Data Protection FOR VmwareIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware+212/11/201817/6/2026
IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.
ModificadaMedia (5.5)0.29%—IBM Tivoli Storage ManagerIBM Tivoli Storage Manager FOR Space ManagementIBM Tivoli Storage Manager FOR Virtual Environments26/9/201817/6/2026
IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696.
ModificadaAlta (7.8)0.28%—IBM Tivoli Storage Manager5/10/201717/6/2026
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.
ModificadaMedia (4.4)0.17%—IBM Tivoli Storage Manager5/10/201717/6/2026
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum protect client or administrator password which can result in information disclosure or a denial of service. IBM X-Force ID: 126247.
ModificadaMedia (5.5)0.36%—IBM Tivoli Storage Manager5/10/201717/6/2026
IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various files on the system, which could allow…
ModificadaCrítica (9.8)1.9%—IBM Tivoli Storage Manager5/10/201717/6/2026
The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to the TSM server. IBM X-Force ID: 118750.
ModificadaMedia (5.5)0.35%—IBM Tivoli Storage Manager7/6/201717/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.
ModificadaMedia (5.5)0.31%—IBM Tivoli Storage Manager5/5/201717/6/2026
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472.
ModificadaAlta (8.8)0.94%—IBM Tivoli Storage Manager7/3/201717/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific…
ModificadaAlta (7.2)1.7%—IBM Tivoli Storage Manager24/2/201717/6/2026
IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on the server. IBM Reference #: 1998747.
ModificadaAlta (8.8)0.55%—IBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR VmwareIBM Tivoli Storage Flashcopy Manager FOR Vmware15/2/201717/6/2026
IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1995545.
ModificadaAlta (7.3)1.0%—IBM Tivoli Storage Manager Fastback8/2/201717/6/2026
IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted DLL in the victim's path, an attacker could exploit this vulnerability when the installer is executed to run arbitrary code on the system with privileges of the victim.
ModificadaMedia (4.7)0.30%—IBM Tivoli Storage Manager FOR Space Management8/2/201717/6/2026
IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace output if the password access option is prompt and the password is changed.
ModificadaMedia (6.5)0.33%—IBM Tivoli Storage ManagerIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware1/2/201717/6/2026
IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user.
ModificadaMedia (5.5)0.34%—IBM Tivoli Storage Manager1/2/201717/6/2026
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.
ModificadaMedia (5.4)0.54%—IBM Tivoli Storage Manager1/2/201717/6/2026
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaAlta (8.8)0.55%—IBM Tivoli Storage Manager1/2/201717/6/2026
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
ModificadaMedia (4.3)0.59%—IBM Tivoli Storage Manager1/2/201717/6/2026
IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.
ModificadaAlta (7)0.23%—IBM Tivoli Storage Manager1/2/201717/6/2026
Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.
ModificadaMedia (6.8)1.00%—IBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware1/2/201717/6/2026
IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges.
ModificadaAlta (7.8)0.42%—IBM Tivoli Storage Manager1/2/201717/6/2026
The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer and execute arbitrary code on the system or cause a system crash.
ModificadaAlta (8.5)0.96%—IBM Tivoli Storage Manager FOR Virtual Environments25/11/201617/6/2026
IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 and 7.1.x before 7.1.6 allows remote authenticated users to bypass a TSM credential requirement and obtain administrative access by leveraging multiple simultaneous logins.
ModificadaMedia (5.5)0.32%—IBM Tivoli Storage Manager FOR Space Management12/9/201617/6/2026
IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted password by reading application-trace output.
ModificadaMedia (6.2)0.37%—IBM Tivoli Storage Flashcopy Manager FOR SQL ServerIBM Tivoli Storage Manager FOR Databases Data Protection FOR Microsoft SQL Server8/8/201617/6/2026
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local…
Orbitaley — Vulnerabilidades