Impact
The vulnerability is a SQL injection flaw in IBM Storage Protect Server 8.2.0 that allows a malicious actor to execute arbitrary SQL statements against the back‑end database. This can enable the attacker to view, add, modify, or delete sensitive data, compromising both confidentiality and integrity of the system’s information. The weakness is classified as CWE‑89.
Affected Systems
IBM Storage Protect Server versions 8.1.0.000 through 8.2.0.xxx and 8.2.1 on AIX Linux and Windows are impacted. The vulnerable endpoint is a JSON‑RPC service exposed by the product, and the vulnerability requires an authenticated session to access it.
Risk and Exploitability
The vulnerability has a CVSS score of 7.6, indicating high severity, but its EPSS score is below 1 % and it does not appear in the CISA KEV catalog, suggesting that exploitation is unlikely at present. The attack vector is remote via the JSON‑RPC endpoint, and the attacker must first authenticate, indicating that the risk is limited to authorized users who could be compromised or granted privileges. Once authenticated, the attacker can manipulate arbitrary data through the injected SQL statements.
OpenCVE Enrichment