Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.
2007-09-28T00:17:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | tivoli_storage_manager_client | 5.1 | Yes |
Application | ibm | tivoli_storage_manager_client | 5.1.8.0 | Yes |
Application | ibm | tivoli_storage_manager_client | 5.2 | Yes |
Application | ibm | tivoli_storage_manager_client | 5.2.5.1 | Yes |
Application | ibm | tivoli_storage_manager_client | 5.3 | Yes |
Application | ibm | tivoli_storage_manager_client | 5.3.5.2 | Yes |
Application | ibm | tivoli_storage_manager_client | 5.4 | Yes |
Application | ibm | tivoli_storage_manager_client | 5.4.1.1 | Yes |