IBM storage protect client是美国IBM公司的一个数据保护客户端软件。 IBM Storage Protect Client和IBM Storage Protect Snapshot For Windows存在信任管理问题漏洞,该漏洞源于FlashCopy Manager(FCM)身份验证机制中使用硬编码凭证,且未正确验证身份验证响应,可能导致远程攻击者绕过身份验证、建立可信会话并访问受保护服务,进而冒充合法客户端导致未授权访问系统资源。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Storage Protect Client | 8.1.0.0≤ 8.2.1.0 |
affected |
| IBM | Storage Protect Snapshot For Windows | 8.1.0.0≤ 8.2.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Storage Protect Client | 8.1.0.0 ~ 8.2.1.0 |
cpe:2.3:a:ibm:storage_protect_client:8.1.0.0:*:*:*:*:*:*:*
|
|
| IBM | Storage Protect Snapshot For Windows | 8.1.0.0 ~ 8.2.1.0 |
cpe:2.3:a:ibm:storage_protect_snapshot_for_windows:8.1.0.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10561 | 10.0 CRITICAL | Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Inj |
| CVE-2026-7664 | 9.8 CRITICAL | Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS |
| CVE-2026-9072 | 8.1 HIGH | WebSphere Application Server Remote Code Execution |
| CVE-2026-9071 | 7.5 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-8858 | 7.5 HIGH | WebSphere Application Server Remote Code Execution |
| CVE-2026-9006 | 7.4 HIGH | IBM WebSphere Application Server is affected by server-side request forgery |
| CVE-2026-8646 | 7.4 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2024-54178 | 6.5 MEDIUM | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud |
| CVE-2024-51454 | 6.5 MEDIUM | IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vuln |
| CVE-2026-8059 | 6.1 MEDIUM | Multiple Vulnerabilities in IBM Datacap |
| CVE-2026-7253 | 6.0 MEDIUM | IBM Sterling File Gateway SQL Injection |
| CVE-2025-2669 | 6.0 MEDIUM | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud |
| CVE-2026-9320 | 5.9 MEDIUM | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-10852 | 5.9 MEDIUM | Websphere Application Server is Affected By a Denial of Service |
| CVE-2026-8636 | 5.5 MEDIUM | Multiple Vulnerabilities in IBM Datacap |
| CVE-2026-11372 | 5.4 MEDIUM | IBM TRIRIGA Cross-Site Scripting Vulnerability |
| CVE-2025-33128 | 5.4 MEDIUM | IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vuln |
| CVE-2023-33854 | 5.3 MEDIUM | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud |
| CVE-2026-9610 | 2.3 LOW | Multiple Vulnerabilities in IBM Datacap |
| CVE-2026-10845 | IBM WebSphere Application Server is affected by an authentication bypass vulnerability |
No comments yet