CVE-2007-4880
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 76%
from disclosure to weapon29 days
Published on NVDSep 28
1st PoC+29d
metasploitSep 24
exploitation probability
76%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/4573unverifiedexploitdbwww.exploit-db.com/exploits/16764unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/38161http://secunia.com/advisories/26883http://securityreason.com/securityalert/3184https://exchange.xforce.ibmcloud.com/vulnerabilities/36700http://www-1.ibm.com/support/docview.wss?uid=swg21268775http://www-1.ibm.com/support/search.wss?rs=0&q=IC52905&apar=onlyhttp://www.securityfocus.com/archive/1/480492http://www.securityfocus.com/bid/25743http://www.securitytracker.com/id?1018725http://www.vupen.com/english/advisories/2007/3228http://www.zerodayinitiative.com/advisories/ZDI-07-054.html