PT-2026-29412 · Ibm · Ibm Storage Protect Plus Server

Published

2026-04-01

·

Updated

2026-04-02

·

CVE-2025-13855

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Storage Protect Server and IBM Storage Protect Plus Server versions 8.2.0
Description IBM Storage Protect Server and IBM Storage Protect Plus Server are susceptible to SQL injection. A remote attacker could submit crafted SQL statements, potentially enabling them to view, add, modify, or delete information within the back-end database.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13855

Affected Products

Ibm Storage Protect Plus Server