CVE-2008-4828

IBM Tivoli Storage Manager Client - Memory Corruption

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-4828. PoCs published by Metasploit, jduck, including Metasploit module exploits/windows/misc/ibm_tsm_rca_dicugetidentify.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in IBM Tivoli Storage Manager Express RCA Service via a crafted 'dicuGetIdentify' request with an overly long NodeName parameter. It first interacts with the CAD service to start the RCA service and retrieve its port before triggering the vulnerability.

Description

Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16428

This Metasploit module exploits a stack buffer overflow in IBM Tivoli Storage Manager Express RCA Service via a crafted 'dicuGetIdentify' request with an overly long NodeName parameter. It first interacts with the CAD service to start the RCA service and retrieve its port before triggering the vulnerability.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IBM Tivoli Storage Manager Express 5.3.6.2
No auth needed
Prerequisites: Network access to the target system · CAD service running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
by jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/ibm_tsm_rca_dicugetidentify.rb

This Metasploit module exploits a stack buffer overflow in IBM Tivoli Storage Manager Express RCA Service by sending a crafted 'dicuGetIdentify' request with an overly long NodeName parameter. It first interacts with the CAD service to start the RCA service and obtain its port, then triggers the vulnerability to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IBM Tivoli Storage Manager Express 5.3.6.2
No auth needed
Prerequisites: Network access to the target system · CAD service running on the target
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (9)

Core 9
Core References
Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2008-55/
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21384389
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1235
Patch, Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IC59513
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/54232
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/503182/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32604
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50327
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/54231

Scores

EPSS 0.7147
EPSS Percentile 99.3%

Details

CWE
CWE-119
Status published
Products (19)
ibm/tivoli_storage_manager_client 5.1
ibm/tivoli_storage_manager_client 5.1.8.0
ibm/tivoli_storage_manager_client 5.1.8.2
ibm/tivoli_storage_manager_client 5.2
ibm/tivoli_storage_manager_client 5.2.5.1
ibm/tivoli_storage_manager_client 5.2.5.2
ibm/tivoli_storage_manager_client 5.2.5.3
ibm/tivoli_storage_manager_client 5.3
ibm/tivoli_storage_manager_client 5.3.5.2
ibm/tivoli_storage_manager_client 5.3.5.3
... and 9 more
Published May 05, 2009
Tracked Since Feb 18, 2026