CVE-2008-4828
IBM Tivoli Storage Manager Client - Memory Corruption
Title source: ruleDescription
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16428
metasploit
WORKING POC
GREAT
by jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/ibm_tsm_rca_dicugetidentify.rb
References (9)
Scores
EPSS
0.7742
EPSS Percentile
99.0%
Details
CWE
CWE-119
Status
published
Products (19)
ibm/tivoli_storage_manager_client
5.1
ibm/tivoli_storage_manager_client
5.1.8.0
ibm/tivoli_storage_manager_client
5.1.8.2
ibm/tivoli_storage_manager_client
5.2
ibm/tivoli_storage_manager_client
5.2.5.1
ibm/tivoli_storage_manager_client
5.2.5.2
ibm/tivoli_storage_manager_client
5.2.5.3
ibm/tivoli_storage_manager_client
5.3
ibm/tivoli_storage_manager_client
5.3.5.2
ibm/tivoli_storage_manager_client
5.3.5.3
... and 9 more
Published
May 05, 2009
Tracked Since
Feb 18, 2026