Vulnerability record · CVE-2008-4828 · published 5 May 2009
CVE-2008-4828: IBM Tivoli Storage Manager Remote Agent stack buffer overflows
Ibm · Tivoli Storage Manager Client
The Remote Agent Service (dsmagent.exe) in IBM Tivoli Storage Manager client and TSM Express client contains multiple stack-based buffer overflows. A request packet mishandled by a generic string handling function, or a crafted NodeName in a dicuGetIdentifyRequest packet, can overflow the stack and corrupt execution flow. The flaw affects a broad set of 5.1 through 5.4 client builds and is reachable over the network without credentials.
Description
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityUnauthenticated remote code execution with a maximum CVSS 2.0 score and very high EPSS, though the product is legacy and no KEV listing or known exploit code is recorded.
What it is
The Remote Agent Service (dsmagent.exe) in IBM Tivoli Storage Manager client and TSM Express client contains multiple stack-based buffer overflows. A request packet mishandled by a generic string handling function, or a crafted NodeName in a dicuGetIdentifyRequest packet, can overflow the stack and corrupt execution flow. The flaw affects a broad set of 5.1 through 5.4 client builds and is reachable over the network without credentials.
Impact
A remote attacker can execute arbitrary code in the context of the dsmagent.exe service, which typically runs with elevated privileges on the backup client host. Successful exploitation can lead to full compromise of the client system and any data or credentials it handles.
Attack surface
Reached over the network through the Remote Agent Service, exposed via the Web GUI and Java GUI components; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host running an affected TSM client with the agent service reachable is a candidate target.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.71 probability, 99.4th percentile), indicating substantial observed or predicted exploitation activity. References include vendor advisories and patches but no public exploit tags.
What to do
- Apply the IBM fixes referenced in the vendor advisories (swg21384389, IC59513) or upgrade to a supported TSM client release.
- Restrict network access to the Remote Agent Service (dsmagent.exe) to trusted backup servers and management subnets using host and network firewalls.
- Disable the Web GUI and Java GUI agent components where they are not operationally required.
- Run the agent service with the least privilege necessary and isolate backup clients on a segmented management network.
- Monitor vendor advisories for this legacy product line and plan migration off end-of-support 5.x clients.
Detection
- Inspect dsmagent.exe process logs and host event logs for crashes, access violations, or unexpected restarts.
- Alert on inbound connections to the Remote Agent Service port from hosts outside the authorized backup server list.
- Use network IDS signatures for malformed dicuGetIdentifyRequest packets or oversized NodeName fields.
- Baseline normal agent request sizes and flag anomalous or unusually long request packets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-4828 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-4828), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.