← Vulnerability feed

Vulnerability record · CVE-2008-4801 · published 31 October 2008

CVE-2008-4801: Ibm tivoli storage manager client memory buffer overflow vulnerability

Ibm · Tivoli Storage Manager Client

Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the Backup-Archive client 5.1.0.0 through 5.1.8.1, 5.2.0.0 through 5.2.5.2, 5.3.0.0 through 5.3.6.1, 5.4.0.0 through 5.4.2.2, and 5.5.0.0 through 5.5.0.91 in IBM Tivoli Storage Manager (TSM); and the Backup-Archive client in TSM Express; allows remote attackers to execute arbitrary code by sending a large amount of crafted data to a TCP port.

10.0 CVSS 2.0 High EPSS 11% · top 4.1% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the Backup-Archive client 5.1.0.0 through 5.1.8.1, 5.2.0.0 through 5.2.5.2, 5.3.0.0 through 5.3.6.1, 5.4.0.0 through 5.4.2.2, and 5.5.0.0 through 5.5.0.91 in IBM Tivoli Storage Manager (TSM); and the Backup-Archive client in TSM Express; allows remote attackers to execute arbitrary code by sending a large amount of crafted data to a TCP port.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-4801 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4828IBM Tivoli Storage Manager Remote Agent stack buffer overflowsThe Remote Agent Service (dsmagent.exe) in IBM Tivoli Storage Manager client and TSM Express client contains multiple stack-based buffer overflows. A…EPSS 71%analysed10.0CVE-2009-1520Ibm tivoli storage manager client memory buffer overflow vulnerabilityBuffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6…EPSS 3.3%10.0CVE-2008-4563Ibm tivoli storage manager memory buffer overflow vulnerabilityHeap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Exp…EPSS 29%10.0CVE-2008-0247Ibm tivoli storage manager express memory buffer overflow vulnerabilityHeap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows re…EPSS 8.5%10.0CVE-2007-4880IBM Tivoli Storage Manager Client CAD Buffer Overflow via HTTP HeadersThe Client Acceptor Daemon (dsmcad.exe) in certain IBM Tivoli Storage Manager clients contains a buffer overflow that can be triggered by crafted HTT…EPSS 76%analysed7.5CVE-2009-1521Ibm tivoli storage manager client vulnerabilityUnspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 th…EPSS 1.7%7.1CVE-2009-1522Ibm tivoli storage manager client vulnerabilityThe IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspeci…EPSS 2.1%5.0CVE-2007-5022Ibm tivoli storage manager client information exposure vulnerabilityUnspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 bef…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2008-4801), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.