peter bassill · operator
$ cve CVE-2009-3853 JSON

CVE-2009-3853 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 36.7% (pctl 98)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via crafted data in a TCP packet.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS36.72% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2009-11-04
Last modified2026-06-16

Affected (1)

VendorProduct
ibmtivoli storage manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD