Vulnerability Details CVE-2015-4951
Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted Web client URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 75.0%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2015-4951
-
cpe:2.3:a:ibm:tivoli_storage_manager:5.5
-
cpe:2.3:a:ibm:tivoli_storage_manager:6.1
-
cpe:2.3:a:ibm:tivoli_storage_manager:6.2
-
cpe:2.3:a:ibm:tivoli_storage_manager:6.3
-
cpe:2.3:a:ibm:tivoli_storage_manager:6.4
-
cpe:2.3:a:ibm:tivoli_storage_manager:7.1