{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-13473","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2026-06-26T21:18:23.722Z","datePublished":"2026-07-17T19:58:31.025Z","dateUpdated":"2026-07-23T03:56:12.789Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-07-17T19:58:31.025Z"},"title":"IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow","affected":[{"vendor":"IBM","product":"Storage Protect Client","versions":[{"status":"affected","version":"8.1.0.0","lessThanOrEqual":"8.1.27.0, 8.1.27.1","versionType":"semver"},{"status":"affected","version":"8.2.0.0","lessThanOrEqual":"8.2.1.0","versionType":"semver"}],"cpes":["cpe:2.3:a:ibm:storage_protect_client:8.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_protect_client:8.1.27.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_protect_client:8.2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:storage_protect_client:8.2.1.0:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7279728","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"HIGH","baseScore":8.1,"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}}],"solutions":[{"lang":"en","value":"IBM strongly recommends addressing the vulnerability now.\n\nProductFixing levelPlatformsLink to fix and instructionsIBM Storage Protect Client8.2.1.2Windows https://www.ibm.com/support/pages/node/7267111 \n\n\n\n\n\nDetails about the upgrade path to be followed for IBM Storage Protect Backup-Archive Client:\n\n\n\nManual Upgrade:\n\nCurrent version Upgrade Path8.1.0.0 - 8.1.27.0, 8.1.27.18.1.0.0 to 8.2.1.0 to 8.2.1.28.2.0.0 - 8.2.1.08.2.0.0 to 8.2.1.2\n\n\n\nUpgrade via Client Auto Deploy \n\n8.1.0.0 - 8.1.27.0, 8.1.27.18.1.27.0 to 8.2.0.0 to 8.2.1.2 , 8.1.27.1 to 8.2.0.0 to 8.2.1.28.2.0.08.2.1.2","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM strongly recommends addressing the vulnerability now.</p><div><table><tbody><tr><td><strong>Product</strong></td><td><strong>Fixing level</strong></td><td><strong>Platforms</strong></td><td><strong>Link to fix and instructions</strong></td></tr><tr><td>IBM Storage Protect Client</td><td>8.2.1.2</td><td>Windows</td><td><a href=\"https://www.ibm.com/support/pages/node/7267111\" rel=\"nofollow\">https://www.ibm.com/support/pages/node/7267111</a></td></tr></tbody></table></div><div></div><p>Details about the upgrade path to be followed for IBM Storage Protect Backup-Archive Client:</p><p>Manual Upgrade:</p><div><table><colgroup><col/><col/></colgroup><tbody><tr><td><strong>Current version </strong></td><td><strong>Upgrade Path</strong></td></tr><tr><td>8.1.0.0 - 8.1.27.0, 8.1.27.1</td><td>8.1.0.0 to 8.2.1.0 to 8.2.1.2</td></tr><tr><td>8.2.0.0 - 8.2.1.0</td><td>8.2.0.0 to 8.2.1.2</td></tr></tbody></table></div><p>Upgrade via Client Auto Deploy </p><div><table><colgroup><col/><col/></colgroup><tbody><tr><td>8.1.0.0 - 8.1.27.0, 8.1.27.1</td><td>8.1.27.0 to 8.2.0.0 to 8.2.1.2 , 8.1.27.1 to 8.2.0.0 to 8.2.1.2</td></tr><tr><td>8.2.0.0</td><td>8.2.1.2</td></tr></tbody></table></div>"}]}],"credits":[{"lang":"en","value":"The vulnerability was reported to IBM by Pétur Eyþórsson and Cristie Nordic.","type":"finder"}],"x_generator":{"engine":"ibm-cvegen"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-122","lang":"en","description":"CWE-122 Heap-based Buffer Overflow"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-22T00:00:00+00:00","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-13473"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-23T03:56:12.789Z"}}]}}