PT-2026-29412 · Ibm · Ibm Storage Protect Plus Server
Published
2026-04-01
·
Updated
2026-04-02
·
CVE-2025-13855
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Storage Protect Server and IBM Storage Protect Plus Server versions 8.2.0
Description
IBM Storage Protect Server and IBM Storage Protect Plus Server are susceptible to SQL injection. A remote attacker could submit crafted SQL statements, potentially enabling them to view, add, modify, or delete information within the back-end database.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Storage Protect Plus Server