RULE(RULE ID:710178)

Rule General Information
Release Date: 2019-12-30
Rule Name: IBM Tivoli Storage Manager FastBack Server Opcode 1331 rmdir Command Injection Vulnerability (CVE-2015-1923)
Severity:
CVE ID:
Rule Protection Details
Description: A command injection vulnerability exists in IBM Tivoli Storage Manager FastBack Server 6.1 before 6.1.12. The vulnerability is due to insufficient input validation of parameters in opcode 1331 requests. A remote unauthenticated attacker can exploit this vulnerability by sending crafted requests to port 11460/TCP. Successful exploitation results in arbitrary command execution within the security context of System.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: SecurityFocusBID:75445
SecurityTrackerID:1032773
ZeroDayInitiative:ZDI-15-264
http://www-01.ibm.com/support/docview.wss?uid=swg21959398
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www-01.ibm.com/support/docview.wss?uid=swg21959398