Executive brief
IBM Storage Protect, a data backup and recovery solution, contains a vulnerability where hardcoded credentials can be used to bypass security checks. An attacker could use these static credentials to impersonate legitimate users and gain unauthorized access to protected backup services and system resources. On Windows systems, this could potentially allow an attacker to gain full administrative (SYSTEM-level) control over the affected machine.
Technical details
A vulnerability exists in the FlashCopy Manager (FCM) authentication mechanism of IBM Storage Protect Client and Snapshot for Windows. The application utilizes hardcoded, static credentials within multiple authentication code paths and fails to properly validate authentication responses. A remote attacker can exploit this by using the static credentials to establish a trusted session without valid unique user credentials. Successful exploitation allows for the impersonation of legitimate clients and unauthorized access to protected services, potentially leading to SYSTEM-level access on Windows platforms. While the hardcoded strings exist in other platform versions (AIX, Linux, etc.), they are reportedly not actively used in those environments.
Affected products
- IBM Storage Protect Client 8.1.0.0 - 8.2.1.0
- IBM Storage Protect Snapshot For Windows 8.1.0.0 - 8.2.1.0
Timeline
- 2026-06-21: advisory: Initial publication of IBM security bulletin
- 2026-06-22: disclosed: NVD publication date