← Vulnerability feed

Vulnerability record · CVE-2007-4348 · published 30 October 2007

CVE-2007-4348: Ibm tivoli storage manager client cross-site scripting vulnerability

Ibm · Tivoli Storage Manager Client

Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.

4.3 CVSS 2.0 Medium EPSS 1.2% · top 32.5% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-4348 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4828IBM Tivoli Storage Manager Remote Agent stack buffer overflowsThe Remote Agent Service (dsmagent.exe) in IBM Tivoli Storage Manager client and TSM Express client contains multiple stack-based buffer overflows. A…EPSS 71%analysed10.0CVE-2009-1520Ibm tivoli storage manager client memory buffer overflow vulnerabilityBuffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6…EPSS 3.3%10.0CVE-2008-4801Ibm tivoli storage manager client memory buffer overflow vulnerabilityHeap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the B…EPSS 11%10.0CVE-2007-4880IBM Tivoli Storage Manager Client CAD Buffer Overflow via HTTP HeadersThe Client Acceptor Daemon (dsmcad.exe) in certain IBM Tivoli Storage Manager clients contains a buffer overflow that can be triggered by crafted HTT…EPSS 76%analysed7.5CVE-2009-1521Ibm tivoli storage manager client vulnerabilityUnspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 th…EPSS 1.7%7.1CVE-2009-1522Ibm tivoli storage manager client vulnerabilityThe IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspeci…EPSS 2.1%5.0CVE-2007-5022Ibm tivoli storage manager client information exposure vulnerabilityUnspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 bef…EPSS 2.0%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed

Source: NIST National Vulnerability Database (record CVE-2007-4348), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.