Stack-based Buffer Overflows in IBM Tivoli Storage Manager Remote Agent Service
CVE-2008-4828 
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 5 May 2009
What is CVE-2008-4828?
The IBM Tivoli Storage Manager (TSM) client suffers from multiple stack-based buffer overflows in dsmagent.exe within the Remote Agent Service. These vulnerabilities can be leveraged by remote attackers to execute arbitrary code. The overflow can be triggered through a malformed request packet that is improperly handled by a generic string processing function or by a crafted NodeName in the dicuGetIdentifyRequest packet. This issue is present across a range of versions, impacting both the Web and Java GUI interfaces.