CVE-2025-13855 is a high-severity SQL injection vulnerability impacting IBM Storage Protect Server 8.2.0 and IBM Storage Protect Plus Server. This allows a remote, low-privileged attacker to execute specially crafted SQL statements with low complexity, leading to full compromise of the back-end database, including data viewing, modification, and deletion. With a CVSS score of 8.8 (HIGH), the vulnerability is considered critical due to its potential for complete data compromise. Although not currently in CISA's KEV catalog and lacking public exploit code, it is designated as "Active" on a hot list and has garnered some community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.2.0CPE matchmatch criteria | cpe:2.3:a:ibm:storage_protect_server:8.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.