CVE-2002-0541
Status: ModifiedHigh (7.5)—
Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 1580 or port 1581.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 4.00%
- Percentile among all scored CVEs: 90
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0126.html
- http://online.securityfocus.com/archive/1/267143
- http://www.iss.net/security_center/static/8817.php
- http://www.iss.net/security_center/static/8825.php
- http://www.securityfocus.com/bid/4492
- http://www.securityfocus.com/bid/4500
- http://www.tivoli.com/support/storage_mgr/flash_httpport.html
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0126.html
- http://online.securityfocus.com/archive/1/267143
- http://www.iss.net/security_center/static/8817.php
- http://www.iss.net/security_center/static/8825.php
- http://www.securityfocus.com/bid/4492
- http://www.securityfocus.com/bid/4500
- http://www.tivoli.com/support/storage_mgr/flash_httpport.html
Raw JSON (NVD)
Show
{
"id": "CVE-2002-0541",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-07-03T04:00:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-04/0126.html",
"source": "cve@mitre.org"
},
{
"url": "http://online.securityfocus.com/archive/1/267143",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/8817.php",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/8825.php",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/4492",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/4500",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.tivoli.com/support/storage_mgr/flash_httpport.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-04/0126.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://online.securityfocus.com/archive/1/267143",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/8817.php",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/8825.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/4492",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/4500",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.tivoli.com/support/storage_mgr/flash_httpport.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 1580 or port 1581."
},
{
"lang": "es",
"value": "Desbordamiento de búfer en Tivoli Storage Manager TSM :\r\n\r\nServer o Storage Agents 3.1 a la 5.1\r\nTSM Client Acceptor Service 4.2 y 5.1\r\n\r\npermite a atacantes remotos realizar un ataque de Denegación de Servicio (caida) y posiblemente la ejecución de código arbitrario mediante una petición HTTP GET larga a los puertos 1580 o 1581."
}
],
"lastModified": "2026-06-16T21:57:38.393",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager:4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "74E4A983-9053-405D-BA3D-BAE8B47A1EB8"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_storage_manager:4.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB1B6BE3-9554-41DF-A994-82CEAF88BA90"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}