A buffer overflow vulnerability exists in the server component of IBM Tivoli Storage Manager FastBack versions 5.5.x and 6.x prior to 6.1.12.2. The vulnerability allows remote attackers to execute arbitrary code by sending a specially crafted command to the server. This issue is distinct from CVE-2015-8519, CVE-2015-8520, and CVE-2015-8521.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python exploit for CVE-2015-8522 affecting IBM Tivoli FastBack Server 6.1.4 on Windows x86. The structure is compact and purpose-built: exploit.py is the main orchestrator; modules/network/server.py implements the proprietary packet format and target interactions; modules/network/client.py creates a local listener and interactive shell handler; modules/network/invite.py contains the x86 reverse-shell shellcode generator; modules/auxiliary/bypass.py builds ASLR/DEP bypass logic and the ROP chain; modules/auxiliary/logger.py provides console output; readme.md documents the vulnerability and exploitation flow. Operationally, the exploit takes a target IPv4 address, connects to the remote service on TCP/11460, and uses a debug-like symbol resolution feature (opcode 0x2000 with SymbolOperation) to leak symbol addresses from the target. It resolves N98E_CRYPTO_get_new_lockid and subtracts offset 0x14E0 to recover the base of libeay32IBM019.dll, then resolves WriteProcessMemory and constructs a ROP chain to bypass DEP/NX. Both the derived base and generated ROP buffer are checked for bad characters; if unsuitable, the exploit intentionally crashes/restarts the service via the vulnerable opcode 0x0534 path and retries until a usable layout is found or timeout is exceeded. Once mitigations are bypassed, the exploit sends an overflow buffer through the vulnerable _FXCLI_SetConfFileChunk path ('File: %s From: 0 To: 0 ChunkLoc: 0 FileLoc: 0'), overwriting control flow and pivoting into the ROP chain. The ROP uses WriteProcessMemory to place the shellcode into an executable code cave, then transfers execution to it. The shellcode loads ws2_32.dll, creates a socket, connects back to the attacker listener using the local host/ephemeral port discovered at runtime, and launches cmd.exe with redirected stdin/stdout/stderr, yielding an interactive reverse shell. The exploit is not part of a larger framework and is a real exploit rather than a detector. It is best classified as OPERATIONAL: it includes a working payload and automated mitigation bypasses, but the payload behavior is fixed to a reverse cmd shell rather than being broadly modular.
This repository is a standalone Python exploit for CVE-2015-8522 against IBM Tivoli FastBack Server 6.1.4 on Windows x86. The codebase is small and organized into a main launcher (exploit.py), auxiliary helpers for logging and mitigation bypass construction, and network modules for target interaction, listener setup, and shellcode generation. The main flow in exploit.py validates a target IPv4 address, creates a local listener object, builds reverse-shell shellcode through the Invite class, and then attempts mitigation bypasses against the remote service at TCP/11460. The bypass routine repeatedly connects to the target, uses a debug-style symbol resolution feature ('SymbolOperation' over opcode 0x2000) to resolve N98E_CRYPTO_get_new_lockid, subtracts offset 0x14E0 to recover the base of libeay32IBM019.dll, and rejects bases containing bad characters. It then resolves WriteProcessMemory and constructs a ROP chain in modules/auxiliary/bypass.py to defeat DEP/NX by writing shellcode into a code cave and pivoting execution to it. If bad characters are encountered in the derived base or ROP chain, the exploit intentionally crashes/restarts the service via the vulnerable opcode 0x0534 path and retries for up to about 10 minutes. modules/network/server.py implements the custom packet format and the two key remote actions: resolve(), which sends a SymbolOperation request to recover symbol addresses from the target, and corrupt(), which sends a crafted 'File: %s From: 0 To: 0 ChunkLoc: 0 FileLoc: 0' buffer to the vulnerable handler to either crash the service or deliver the final overflow payload. modules/network/invite.py contains a large embedded x86 shellcode blob that dynamically resolves APIs, loads ws2_32.dll, creates a socket, connects back to the attacker-controlled host and port, and launches cmd.exe with redirected standard handles. modules/network/client.py starts a local TCP listener on a runtime-selected ephemeral port and provides a minimal interactive command loop once the target connects back. modules/auxiliary/logger.py is only terminal output support. Overall, this is a real exploit rather than a scanner or detector. Its primary capability is unauthenticated remote code execution over the network, culminating in a reverse interactive Windows command shell. The exploit is operational but not framework-based: the payload is embedded and generated automatically, but customization is limited to the attacker host and chosen listener port at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.