Security Bulletin
Summary
IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Space Management are vulnerable to stack-based buffer overflows caused by improper bounds checking. UDPATED: 14 June 2021 - Added 7.1 fix. UPDATED: 25 June 2021 - Added 8.1.9.2 fix for Macintosh
Vulnerability Details
CVEID: CVE-2021-29672
DESCRIPTION: IBM Spectrum Protect client is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when processing the current locale settings. A local attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges or cause the application to crash.
CVSS Base score: 8.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199479 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2021-20546
DESCRIPTION: IBM Spectrum Protect Client is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and cause the application to crash.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/198934 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Affected Products and Versions
Affected Product(s) | Version(s) |
IBM Spectrum Protect Backup-Archive Client | 8.1.0.0-8.1.11.0 7.1.0.0-7.1.8.10 |
IBM Spectrum Protect for Space Management | 8.1.0.0-8.1.11.0 7.1.0.0-7.1.8.10 |
Remediation/Fixes
IBM Spectrum Protect Backup-Archive Client Release | First Fixing VRM Level | Platform | Link to Fix |
8.1 | 8.1.12 | AIX Linux Macintosh Solaris Windows | https://www.ibm.com/support/pages/node/6443671 |
8.1 | 8.1.9.2* | Macintosh* | https://www.ibm.com/support/pages/node/589103 |
7.1 | 7.1.8.11 | AIX HP-UX Linux Macintosh Solaris Windows | https://www.ibm.com/support/pages/node/316619 |
*An 8.1.9.2 fix was provided for Macintosh because the Spectrum Protect Backup-Archive Client was stabilized at 8.1.9 for older Mac OS levels.
Refer to https://www.ibm.com/support/pages/node/660995 for more information.
IBM Spectrum Protect for Space Management Release | First Fixing VRM Level | Platform | Link to Fix |
8.1 | 8.1.12 | AIX Linux | https://www.ibm.com/support/pages/node/6416187 |
7.1 | 7.1.8.11 | AIX Linux | https://www.ibm.com/support/pages/node/316075 |
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Acknowledgement
Change History
23 Apr 2021: Initial Publication
14 June 2021: Added 7.1 fix
25 June 2021 - Added 8.1.9.2 fix for Macintosh
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
25 June 2021
UID
ibm16445497