← Vulnerability feed

Vulnerability record · CVE-2008-4828 · published 5 May 2009

CVE-2008-4828: IBM Tivoli Storage Manager Remote Agent stack buffer overflows

Ibm · Tivoli Storage Manager Client

The Remote Agent Service (dsmagent.exe) in IBM Tivoli Storage Manager client and TSM Express client contains multiple stack-based buffer overflows. A request packet mishandled by a generic string handling function, or a crafted NodeName in a dicuGetIdentifyRequest packet, can overflow the stack and corrupt execution flow. The flaw affects a broad set of 5.1 through 5.4 client builds and is reachable over the network without credentials.

10.0 CVSS 2.0 High EPSS 71% · top 0.6% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with a maximum CVSS 2.0 score and very high EPSS, though the product is legacy and no KEV listing or known exploit code is recorded.

What it is

The Remote Agent Service (dsmagent.exe) in IBM Tivoli Storage Manager client and TSM Express client contains multiple stack-based buffer overflows. A request packet mishandled by a generic string handling function, or a crafted NodeName in a dicuGetIdentifyRequest packet, can overflow the stack and corrupt execution flow. The flaw affects a broad set of 5.1 through 5.4 client builds and is reachable over the network without credentials.

Impact

A remote attacker can execute arbitrary code in the context of the dsmagent.exe service, which typically runs with elevated privileges on the backup client host. Successful exploitation can lead to full compromise of the client system and any data or credentials it handles.

Attack surface

Reached over the network through the Remote Agent Service, exposed via the Web GUI and Java GUI components; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host running an affected TSM client with the agent service reachable is a candidate target.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.71 probability, 99.4th percentile), indicating substantial observed or predicted exploitation activity. References include vendor advisories and patches but no public exploit tags.

What to do

  • Apply the IBM fixes referenced in the vendor advisories (swg21384389, IC59513) or upgrade to a supported TSM client release.
  • Restrict network access to the Remote Agent Service (dsmagent.exe) to trusted backup servers and management subnets using host and network firewalls.
  • Disable the Web GUI and Java GUI agent components where they are not operationally required.
  • Run the agent service with the least privilege necessary and isolate backup clients on a segmented management network.
  • Monitor vendor advisories for this legacy product line and plan migration off end-of-support 5.x clients.

Detection

  • Inspect dsmagent.exe process logs and host event logs for crashes, access violations, or unexpected restarts.
  • Alert on inbound connections to the Remote Agent Service port from hosts outside the authorized backup server list.
  • Use network IDS signatures for malformed dicuGetIdentifyRequest packets or oversized NodeName fields.
  • Baseline normal agent request sizes and flag anomalous or unusually long request packets.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-4828 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1520Ibm tivoli storage manager client memory buffer overflow vulnerabilityBuffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6…EPSS 3.3%10.0CVE-2008-4563Ibm tivoli storage manager memory buffer overflow vulnerabilityHeap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Exp…EPSS 29%10.0CVE-2008-4801Ibm tivoli storage manager client memory buffer overflow vulnerabilityHeap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the B…EPSS 11%10.0CVE-2008-0247Ibm tivoli storage manager express memory buffer overflow vulnerabilityHeap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows re…EPSS 8.5%10.0CVE-2007-4880IBM Tivoli Storage Manager Client CAD Buffer Overflow via HTTP HeadersThe Client Acceptor Daemon (dsmcad.exe) in certain IBM Tivoli Storage Manager clients contains a buffer overflow that can be triggered by crafted HTT…EPSS 76%analysed7.5CVE-2009-1521Ibm tivoli storage manager client vulnerabilityUnspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 th…EPSS 1.7%7.1CVE-2009-1522Ibm tivoli storage manager client vulnerabilityThe IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspeci…EPSS 2.1%5.0CVE-2007-5022Ibm tivoli storage manager client information exposure vulnerabilityUnspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 bef…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2008-4828), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.