CVE-2009-3853 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 36.7% (pctl 98)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via crafted data in a TCP packet.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 36.72% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-11-04 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | tivoli storage manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IBM Tivoli Storage Manager Express CAD Service - Remote Buffer Overflow (Metasploit) (1) | 2010-05-09 |
References
- http://secunia.com/advisories/32534
- http://secunia.com/secunia_research/2008-51/
- http://securitytracker.com/id?1023136
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC61036
- http://www-01.ibm.com/support/docview.wss?uid=swg21405562
- http://www.securityfocus.com/archive/1/507654/100/0/threaded
- http://www.vupen.com/english/advisories/2009/3132
- http://secunia.com/advisories/32534
- http://secunia.com/secunia_research/2008-51/
- http://securitytracker.com/id?1023136
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC61036
- http://www-01.ibm.com/support/docview.wss?uid=swg21405562
- http://www.securityfocus.com/archive/1/507654/100/0/threaded
- http://www.vupen.com/english/advisories/2009/3132
→ the Explorer · watch your stack · NVD