Ibm Storage Protect Client vulnerabilities
4 known vulnerabilities affecting ibm/storage_protect_client.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-12628P2CRITICALCVSS 9.1≥ 8.1.0.0, ≤ 8.2.1.02026-06-22
CVE-2026-12628 [CRITICAL] CWE-798 CVE-2026-12628: IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentica
nvd
CVE-2026-13473P3CRITICALCVSS 9.8≥ 8.1.0.0, ≤ 8.1.27.0, 8.1.27.1≥ 8.2.0.0, ≤ 8.2.1.02026-07-17
CVE-2026-13473 [CRITICAL] CWE-122 CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Stora
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.
nvd
CVE-2023-35897P3HIGHCVSS 7.8≥ 8.1.0.0, ≤ 8.1.19.02023-10-06
CVE-2023-35897 [HIGH] CWE-94 CVE-2023-35897: IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.
IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246.
nvd
CVE-2023-40368P4MEDIUMCVSS 4.4≥ 8.1.0.0, ≤ 8.1.19.02023-09-20
CVE-2023-40368 [MEDIUM] CWE-200 CVE-2023-40368: IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive infor
IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the administrative command line client. IBM X-Force ID: 263456.
nvd