IBM Support

Security Bulletin: A security vulnerability has been identified in the IBM Spectrum Protect Client that affects multiple IBM Spectrum Protect products (CVE-2018-1786)

Created by Robyn Stillwell on
Published URL:
https://www.ibm.com/support/pages/node/740175
740175

Security Bulletin


Summary

The IBM Spectrum Protect (formerly Tivoli Storage Manger) Client/API is used as a component of IBM Spectrum Protect Snapshot (formerly Tivoli Storage FlashCopy Manager) for Windows, IBM Spectrum Protect for Databases, and IBM Spectrum Protect for Mail. Information about a security vulnerability affecting the IBM Spectrum Protect Client/API has been published in a security bulletin.

Vulnerability Details

Consult the security bulletin Denial of Service vulnerability affects IBM Spectrum Protect Client and IBM Spectrum Protect for Virtual Environments (CVE-2018-1786) for vulnerability details and information about the fixes.

Affected Products and Versions

Principal Product and Version(s)

Affected Supporting Product and Version
IBM Spectrum Protect Snapshot for Windows version 8.1 IBM Spectrum Protect Client/API version 8.1.
IBM Spectrum Protect Snapshot (formerly Tivoli Storage FlashCopy Manager) for Windows version 4.1 IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage FlashCopy Manager for Windows version 6.4 and below are EOS.  IBM recommends upgrading to a supported level. Tivoli Storage Manager Client/API version 6.4 and below are EOS.  IBM recommends upgrading to a supported level.

Note: Within the IBM Spectrum Protect Snapshot on Windows product, the IBM Spectrum Protect  Client is also referred to as the FlashCopy Manager VSS Requestor component.

 

Principal Product and Version(s)

Affected Supporting Product and Version
IBM Spectrum Protect for Databases: Data Protection for Microsoft SQL Server version 8.1 IBM Spectrum Protect Client/API version 8.1.
IBM Spectrum Protect for Databases (formerly Tivoli Storage Manager for Databases): Data Protection for Microsoft SQL Server version 7.1 IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server version 6.4 and below are EOS.  IBM recommends upgrading to a supported level. Tivoli Storage Manager Client/API version 6.4 and below are EOS.  IBM recommends upgrading to a supported level.

 

Principal Product and Version(s)

Affected Supporting Product and Version
IBM Spectrum Protect for Databases: Data Protection for Oracle version 8.1 IBM Spectrum Protect Client/API version 8.1.
IBM Spectrum Protect for Databases (formerly Tivoli Storage Manager for Databases): Data Protection for Oracle version 7.1 IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage Manager for Databases: Data Protection for Oracle version 6.4 and below are EOS.  IBM recommends upgrading to a supported level. Tivoli Storage Manager Client/API version 6.4 and below are EOS.  IBM recommends upgrading to a supported level.

 

Principal Product and Version(s)

Affected Supporting Product and Version
IBM Spectrum Protect for Mail: Data Protection for Microsoft Exchange Server version 8.1 IBM Spectrum Protect Client/API version 8.1.
IBM Spectrum Protect for Mail (formerly Tivoli Storage Manager for Mail): Data Protection for Microsoft Exchange Server version 7.1 IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server version 6.4 and below are EOS.  IBM recommends upgrading to a supported level. Tivoli Storage Manager Client/API version 6.4 and below are EOS.  IBM recommends upgrading to a supported level.

 

Principal Product and Version(s)

Affected Supporting Product and Version
IBM Spectrum Protect for Mail (formerly Tivoli Storage Manager for Mail): Data Protection for Domino version 7.1 IBM Spectrum Protect (formerly Tivoli Storage Manager) Client/API version 7.1
Tivoli Storage Manager for Mail: Data Protection for Domino version 6.4 and below are EOS.  IBM recommends upgrading to a supported level.

Tivoli Storage Manager Client/API version 6.4 and below are EOS.  IBM recommends upgrading to a supported level.

 

Get Notified about Future Security Bulletins

References

Off

Change History

13 November 2018 - Original version published.
14 November 2018 - Removed Data Protection for Domino 8.1 as this is incorrect

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Internal Use Only

Advisory 13052 126134

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSERFV","label":"IBM Spectrum Protect Snapshot"},"Component":"","Platform":[{"code":"PF033","label":"Windows"}],"Version":"8.1;4.1","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSER7G","label":"IBM Spectrum Protect for Databases"},"Component":"","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"8.1;7.1","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSERBW","label":"IBM Spectrum Protect for Mail"},"Component":"","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"8.1;7.1","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SS36V9","label":"Tivoli Storage FlashCopy Manager"},"Component":"","Platform":[{"code":"PF033","label":"Windows"}],"Version":"4.1","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSTFZR","label":"Tivoli Storage Manager for Databases"},"Component":"","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"7.1","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSTG2D","label":"Tivoli Storage Manager for Mail"},"Component":"","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"7.1","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
01 February 2022

UID

ibm10740175