CVE-2010-3757

Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string.  NOTE: this might overlap CVE-2010-3059.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
ibmtivoli_storage_manager_fastback
5.5.0
ibmtivoli_storage_manager_fastback
5.5.1
ibmtivoli_storage_manager_fastback
5.5.2
ibmtivoli_storage_manager_fastback
5.5.2.0
ibmtivoli_storage_manager_fastback
5.5.3.0
ibmtivoli_storage_manager_fastback
5.5.4.0
ibmtivoli_storage_manager_fastback
5.5.5.0
ibmtivoli_storage_manager_fastback
5.5.6.0
ibmtivoli_storage_manager_fastback
6.1.0.0
ibmtivoli_storage_manager_fastback
6.1.0.1
𝑥
= Vulnerable software versions