IBM Storage Protect Server
cpe:2.3:a:ibm:spectrum_protect_server:*:*:*:*:*:*:*
- >= 8.1.0.000, <= 8.2.0.xxx
A SQL injection vulnerability has been identified in IBM Storage Protect Server version 8.2.0. This issue allows remote attackers to send specially crafted SQL statements that could be used to view, add, modify, or delete information in the back-end database. The vulnerability arises from improper neutralization of special elements used in SQL commands, enabling attackers to manipulate database queries and access or alter database information.
Exploitation of this vulnerability could lead to unauthorized access to the back-end database, allowing attackers to execute SQL commands that could manipulate database information. This includes the potential to view, add, modify, or delete data, which could disrupt normal operations or lead to unauthorized disclosure of sensitive information.
Users can upgrade to IBM Storage Protect Server version 8.2.1 to address this vulnerability. Instructions for downloading the update are available on the IBM Support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.