Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-28054 PoC — TSMManager Collector 信息泄露漏洞

Source
Associated Vulnerability
Title:TSMManager Collector 信息泄露漏洞 (CVE-2020-28054)
Description:Tsmmanager TSMManager Collector是美国TSMManager(Tsmmanager)公司的一个可以对分布式存储管理器、Tivoli 存储管理器、磁盘存储管理器进行监视、管理,操作,控制的软件。 JamoDat TSMManager Collector 6.5.0.21版本存在信息泄露漏洞,该漏洞源于收集器组件没有正确地向查看器验证经过身份验证的会话,攻击者可利用该漏洞可以请求每个收集器的功能就像一个正常登录用户:管理连接的情况下,检查日志,编辑配置,访问实例的主机,访问硬件配置
Description
Advisory for CVE-2020-28054 & stack based buffer overflow in IBM Tivoli Storage Manager
Readme
# Tivoli-Madness
Advisory for:

+ CVE-2020-28054: An Authorization Bypass vulnerability affecting JamoDat – TSMManager Collector v. <= 6.5.0.21
+ A Stack Based Buffer Overflow affecting IBM Tivoli Storage Manager (Command Line Administrative Interface) Version 5, Release 2, Level 0.1. 

	Unfortunately, after I had one of the rudest encounters with an Hackerone’s triager, these are the takeaways: 
	+ IBM Tivoli Storage Manager has reached its end of life support and will not be patched.
	+ No CVE number was released.
	+ I cannot verify if this vulnerability is also affecting the newer IBM Spectrum Protect, so, good luck with that.

### You can read more on: [https://voidsec.com/tivoli-madness](https://voidsec.com/tivoli-madness)
File Snapshot

[4.0K] /data/pocs/0086a1df941aab6fcbd36af649ab1e389b60c8d2 ├── [1.4K] CreateProcessPoC.cpp ├── [4.0K] IBM - ITSM Administrator Client │   ├── [1.0M] IBM_ITSM_Administrator_Client_v.5.2.0.1.zip │   └── [7.2K] IBM_TSM_v.5.2.0.1_exploit.py ├── [4.0K] JamoDat - TSMManager │   ├── [1.6K] TSM_Client.py │   ├── [ 13M] TSMmgr_client_patched.exe │   ├── [ 19M] TSMMgr_Collector_v.6.3.exe │   └── [7.1M] TSMMgr_Viewer_v.6.3.exe └── [ 741] README.md 2 directories, 8 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.