Vulnerability record · CVE-2007-4880 · published 28 September 2007
CVE-2007-4880: IBM Tivoli Storage Manager Client CAD Buffer Overflow via HTTP Headers
Ibm · Tivoli Storage Manager Client
The Client Acceptor Daemon (dsmcad.exe) in certain IBM Tivoli Storage Manager clients contains a buffer overflow that can be triggered by crafted HTTP headers. A remote, unauthenticated attacker can send malformed headers to the daemon and potentially execute arbitrary code. The flaw affects TSM client versions 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2.
Description
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, combined with a very high EPSS score, makes this a top remediation priority.
What it is
The Client Acceptor Daemon (dsmcad.exe) in certain IBM Tivoli Storage Manager clients contains a buffer overflow that can be triggered by crafted HTTP headers. A remote, unauthenticated attacker can send malformed headers to the daemon and potentially execute arbitrary code. The flaw affects TSM client versions 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2.
Impact
Successful exploitation allows remote code execution with the privileges of the dsmcad.exe process, which can lead to full compromise of the affected client host. An attacker could install malware, steal data, or pivot to other systems reachable from that host.
Attack surface
The vulnerability is reached over the network via the Client Acceptor Daemon's HTTP listener; no authentication or user interaction is required according to the CVSS vector (AV:N/AC:L/Au:N). Any host running an affected TSM client with the CAD service exposed is a potential target.
Exploitation
The record is not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.75945, 99.5th percentile), indicating a strong likelihood of exploitation activity. References include vendor advisories and patch links but no public exploit tag.
What to do
- Apply the IBM fix for APAR IC52905 by upgrading TSM clients to 5.1.8.1, 5.2.5.2, 5.3.5.3, or 5.4.1.2 (or later) as applicable.
- Restrict network access to the Client Acceptor Daemon (dsmcad.exe) listener to trusted management networks only.
- Disable or stop the CAD service on clients that do not require it.
- Monitor IBM advisories and apply subsequent TSM client security updates promptly.
Detection
- Inspect network traffic to the CAD listener for malformed or unusually long HTTP headers.
- Monitor dsmcad.exe process crashes or abnormal terminations on TSM client hosts.
- Review host logs for unexpected child processes or code execution originating from the dsmcad.exe service account.
- Audit exposed TSM client CAD ports and alert on connections from untrusted source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-4880 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-4880), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.