CVE-2018-1786
moderate-risk
Published 2018-11-12
IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.
Do I need to act?
-
0.30% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.3/10
Medium
NETWORK
/ LOW complexity
Affected Products (6)
Spectrum Protect Manager For Virtual Environments Data Protection For Vmware
Tivoli Storage Manager For Virtual Environments Data Protection For Vmware
Spectrum Protect For Virtual Environments Data Protection For Hyper-V
Tivoli Storage Manager For Virtual Environments Data Protection For Hyper-V
Affected Vendors
References (6)
Third Party Advisory
http://www.securityfocus.com/bid/105940
Third Party Advisory
http://www.securityfocus.com/bid/105940
35
/ 100
moderate-risk
Severity
21/34 · High
Exploitability
1/34 · Minimal
Exposure
13/34 · Low