peter bassill · operator
$ cve CVE-2008-4828 JSON

CVE-2008-4828 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 71.5% (pctl 99)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS71.47% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2009-05-05
Last modified2026-06-16

Affected (2)

VendorProduct
ibmtivoli storage manager client
ibmtivoli storage manager express

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD