PT-2026-29412 · Ibm · Ibm Storage Protect Plus Server

CVE-2025-13855

·

Published

2026-03-26

·

Updated

2026-04-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Storage Protect Server and IBM Storage Protect Plus Server versions 8.2.0
Description IBM Storage Protect Server and IBM Storage Protect Plus Server are susceptible to SQL injection. A remote attacker could submit crafted SQL statements, potentially enabling them to view, add, modify, or delete information within the back-end database.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08589
CVE-2025-13855

Affected Products

Ibm Storage Protect Plus Server