Impact
IBM Storage Protect Client is affected by a heap-based buffer overflow caused by improper bounds checking. When triggered, a remote attacker can overflow a memory buffer and either execute arbitrary code on the target system or cause the associated server to crash.
Affected Systems
Systems running IBM Storage Protect Client versions 8.1.0.0 through 8.1.27.0, 8.1.27.1, 8.2.0.0 through 8.2.1.0 are vulnerable. The fixed releases, such as 8.2.1.2, are available through IBM's upgrade path.
Risk and Exploitability
The CVSS score is 8.1, indicating high severity, while the EPSS score of less than 1 % suggests a low current exploitation probability and the vulnerability is not listed in CISA's KEV catalog. The flaw can be triggered remotely, likely over a network connection to the client, and allows arbitrary code execution or denial of service.
OpenCVE Enrichment