← Vulnerability feed

Vulnerability record · CVE-2008-4563 · published 11 March 2009

CVE-2008-4563: Ibm tivoli storage manager memory buffer overflow vulnerability

Ibm · Tivoli Storage Manager

Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.

10.0 CVSS 2.0 High EPSS 29% · top 1.9% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-4563 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-3854Ibm tivoli storage manager memory buffer overflow vulnerabilityBuffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7 and 5.4 before 5.4.2 allows …EPSS 5.8%10.0CVE-2008-4828IBM Tivoli Storage Manager Remote Agent stack buffer overflowsThe Remote Agent Service (dsmagent.exe) in IBM Tivoli Storage Manager client and TSM Express client contains multiple stack-based buffer overflows. A…EPSS 71%analysed10.0CVE-2009-1520Ibm tivoli storage manager client memory buffer overflow vulnerabilityBuffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6…EPSS 3.3%10.0CVE-2009-1178Ibm tivoli storage manager vulnerabilityUnspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vecto…EPSS 2.0%10.0CVE-2008-4801Ibm tivoli storage manager client memory buffer overflow vulnerabilityHeap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the B…EPSS 11%10.0CVE-2008-0247Ibm tivoli storage manager express memory buffer overflow vulnerabilityHeap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows re…EPSS 8.5%10.0CVE-2006-5855Ibm tivoli storage manager vulnerabilityMultiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service…EPSS 27%9.8CVE-2016-8937Ibm tivoli storage manager improper authentication vulnerabilityThe IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclo…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2008-4563), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.