CVE-2025-13855: IBM Storage Protect Server is affected by a vulnerability that could allow authenticated users to access administrative metadata through the JSON-RPC endpoint .
Published Mar 26, 2026
·Updated
IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Affected Software
7 affected componentsFixes available
IBM Storage Protect Server=8.2.0
IBM Storage Protect Plus Server
IBM Storage Protect Server<=8.2.0
All of the following
IBM Storage Protect Server=8.2.0
Any of the following
IBM AIX
Linux Linux kernel
Microsoft Windows
Remediation
Information
Affected VersionsFixing LevelPlatformRemediation/Fix/Instructions8.1.0.000 - 8.2.0.xxx8.2.1AIX Linux WindowsInstructions for downloading the update: https://www.ibm.com/support/pages/node/7266171
Event History
Mar 26, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Apr 1, 2026
CVE Published
via MITRE·12:23 AM
Data Sourced
via MITRE·12:23 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeaknessAffected Software