PT-2026-51331 · Ibm · Storage Protect Client+1
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Storage Protect Client versions 8.1.0.0 through 8.2.1.0
IBM Storage Protect Snapshot For Windows versions 8.1.0.0 through 8.2.1.0
Description
An authentication bypass exists in the FlashCopy Manager (FCM) authentication mechanism. The application uses a hardcoded static credential embedded in multiple authentication code paths and fails to properly validate authentication responses. This allows a remote, unauthenticated attacker to establish a trusted session, impersonate legitimate clients, and gain unauthorized access to protected services and system resources.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Storage Protect Client
Storage Protect Snapshot For Windows