Description
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.
Published: 2026-07-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Storage Protect Client is affected by a heap-based buffer overflow caused by improper bounds checking. When triggered, a remote attacker can overflow a memory buffer and either execute arbitrary code on the target system or cause the associated server to crash.

Affected Systems

Systems running IBM Storage Protect Client versions 8.1.0.0 through 8.1.27.0, 8.1.27.1, 8.2.0.0 through 8.2.1.0 are vulnerable. The fixed releases, such as 8.2.1.2, are available through IBM's upgrade path.

Risk and Exploitability

The CVSS score is 8.1, indicating high severity, while the EPSS score of less than 1 % suggests a low current exploitation probability and the vulnerability is not listed in CISA's KEV catalog. The flaw can be triggered remotely, likely over a network connection to the client, and allows arbitrary code execution or denial of service.

Generated by OpenCVE AI on July 30, 2026 at 23:34 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. ProductFixing levelPlatformsLink to fix and instructionsIBM Storage Protect Client8.2.1.2Windows https://www.ibm.com/support/pages/node/7267111 Details about the upgrade path to be followed for IBM Storage Protect Backup-Archive Client: Manual Upgrade: Current version Upgrade Path8.1.0.0 - 8.1.27.0, 8.1.27.18.1.0.0 to 8.2.1.0 to 8.2.1.28.2.0.0 - 8.2.1.08.2.0.0 to 8.2.1.2 Upgrade via Client Auto Deploy  8.1.0.0 - 8.1.27.0, 8.1.27.18.1.27.0 to 8.2.0.0 to 8.2.1.2 , 8.1.27.1 to 8.2.0.0 to 8.2.1.28.2.0.08.2.1.2


OpenCVE Recommended Actions

  • Upgrade to IBM Storage Protect Client 8.2.1.2 via IBM's official upgrade path.
  • If auto-deploy is unavailable, perform a manual upgrade from any affected 8.1.x or 8.2.0.x release to 8.2.1.2 as instructed by IBM.
  • When an immediate upgrade is not possible, isolate the client from untrusted remote access, apply network segmentation or firewall rules, and monitor for abnormal activity until a patch is applied.

Generated by OpenCVE AI on July 30, 2026 at 23:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Tue, 21 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.
Title IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow
First Time appeared Ibm
Ibm storage Protect Client
CPEs cpe:2.3:a:ibm:storage_protect_client:8.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_protect_client:8.1.27.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_protect_client:8.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_protect_client:8.2.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm storage Protect Client
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Storage Protect Client
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-23T03:56:12.789Z

Reserved: 2026-06-26T21:18:23.722Z

Link: CVE-2026-13473

cve-icon Vulnrichment

Updated: 2026-07-21T02:09:39.823Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:45:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow