← Back to browse · API

CVE-2019-4087

Severity
CRITICAL
CVSS
9.8
EPSS
0.06959
Risk score
41.64
CISA KEV
No
PoC
No
Published
2019-07-02
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2019-13694, GHSA-PWXH-5C57-PHQ7
Products
IBM:Spectrum Protect 7.1, IBM:Spectrum Protect 8.1
Sources
euvd EUVD-2019-13694

Description

IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges. By sending an overly long request, a remote attacker could overflow a buffer and execute arbitrary code on the system with instance id privileges or cause the server or storage agent to crash. IBM X-Force ID: 157510.

References