CVE-2010-3757

EUVD-2010-3736
Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string.  NOTE: this might overlap CVE-2010-3059.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
ibmtivoli_storage_manager_fastback
5.5.0
ibmtivoli_storage_manager_fastback
5.5.1
ibmtivoli_storage_manager_fastback
5.5.2
ibmtivoli_storage_manager_fastback
5.5.2.0
ibmtivoli_storage_manager_fastback
5.5.3.0
ibmtivoli_storage_manager_fastback
5.5.4.0
ibmtivoli_storage_manager_fastback
5.5.5.0
ibmtivoli_storage_manager_fastback
5.5.6.0
ibmtivoli_storage_manager_fastback
6.1.0.0
ibmtivoli_storage_manager_fastback
6.1.0.1
𝑥
= Vulnerable software versions