← Vulnerability feed

Vulnerability record · CVE-2006-5855 · published 6 December 2006

CVE-2006-5855: Ibm tivoli storage manager vulnerability

Ibm · Tivoli Storage Manager

Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in (1) the language field at logon that begins with a 0x18 byte, (2) two unspecified parameters to the SmExecuteWdsfSession function, and (3) the contact field in an open registration message.

10.0 CVSS 2.0 High EPSS 27% · top 2.0%
10.0CVSS 2.0 base score
27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in (1) the language field at logon that begins with a 0x18 byte, (2) two unspecified parameters to the SmExecuteWdsfSession function, and (3) the contact field in an open registration message.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/23177 Vendor Advisory
http://securityreason.com/securityalert/1979
http://securitytracker.com/id?1017333
http://www-1.ibm.com/support/docview.wss?uid=swg1IC50347 PatchVendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg21250261 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/350625 US Government Resource
http://www.kb.cert.org/vuls/id/478753 US Government Resource
http://www.kb.cert.org/vuls/id/887249 US Government Resource
http://www.securityfocus.com/archive/1/453544/100/0/threaded
http://www.securityfocus.com/bid/21440 PatchVendor Advisory
http://www.tippingpoint.com/security/advisories/TSRT-06-14.html Vendor Advisory
http://www.vupen.com/english/advisories/2006/4856
https://exchange.xforce.ibmcloud.com/vulnerabilities/30699
https://exchange.xforce.ibmcloud.com/vulnerabilities/30701
https://exchange.xforce.ibmcloud.com/vulnerabilities/30702
http://secunia.com/advisories/23177 Vendor Advisory
http://securityreason.com/securityalert/1979
http://securitytracker.com/id?1017333
http://www-1.ibm.com/support/docview.wss?uid=swg1IC50347 PatchVendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg21250261 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/350625 US Government Resource
http://www.kb.cert.org/vuls/id/478753 US Government Resource
http://www.kb.cert.org/vuls/id/887249 US Government Resource
http://www.securityfocus.com/archive/1/453544/100/0/threaded
http://www.securityfocus.com/bid/21440 PatchVendor Advisory
http://www.tippingpoint.com/security/advisories/TSRT-06-14.html Vendor Advisory
http://www.vupen.com/english/advisories/2006/4856
https://exchange.xforce.ibmcloud.com/vulnerabilities/30699
https://exchange.xforce.ibmcloud.com/vulnerabilities/30701
https://exchange.xforce.ibmcloud.com/vulnerabilities/30702

Track CVE-2006-5855 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-3854Ibm tivoli storage manager memory buffer overflow vulnerabilityBuffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7 and 5.4 before 5.4.2 allows …EPSS 5.8%10.0CVE-2009-1178Ibm tivoli storage manager vulnerabilityUnspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vecto…EPSS 2.0%10.0CVE-2008-4563Ibm tivoli storage manager memory buffer overflow vulnerabilityHeap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Exp…EPSS 29%9.8CVE-2016-8937Ibm tivoli storage manager improper authentication vulnerabilityThe IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclo…EPSS 1.9%9.3CVE-2009-3853Ibm tivoli storage manager memory buffer overflow vulnerabilityStack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 b…EPSS 37%9.3CVE-2009-3855Ibm tivoli storage manager vulnerabilityMultiple unspecified vulnerabilities in the (1) UNIX and (2) Linux backup-archive clients, and the (3) OS/400 API client, in IBM Tivoli Storage Manag…EPSS 1.7%8.8CVE-2016-8940Ibm tivoli storage manager information exposure vulnerabilityIBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, …EPSS 0.94%8.8CVE-2016-6045Ibm tivoli storage manager cross-site request forgery vulnerabilityIBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2006-5855), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.