Fix Readme
Abstract
What APARs and security fixes have been incorporated in the IBM Storage Protect server Version 8.2 levels?
Content
The following tables list APARs that are addressed in the IBM Storage Protect server V8.2 levels.
Tip: In the following list, Rel represents the release number in which the issue was detected. The operating system is identified (A = AIX, L = Linux, and W = Windows). For example, 82L denotes V8.2 running on a Linux operating system.
APARs fixed in level 8.2.0.000.
Security vulnerabilities fixed in level 8.2.0.000
APARs fixed in level 8.2.1.000
Security vulnerabilities fixed in level 8.2.1.000
APARs fixed in level 8.2.1.200
Security vulnerabilities fixed in level 8.2.1.200
APARs fixed in level 8.2.2.000
Security vulnerabilities fixed in level 8.2.2.000
APARs fixed in level 8.2.0.000
APAR | Severity | Operating System/Release Of Reported Issue (APAR, CompId, Rel) | Abstract |
| 4 | IT42602 5698ISMSV 81L | QUERY REPLNODE WITH A SPECIFIC SERVER STILL SHOWS UP AFTER REMOVE REPLNODE | |
| 3 | IT44363 5698ISMSV 81L | EXPIRATION PROCESS SKIPS EXPIRED OBJECTS WHICH ARE REPLICATED BY STORAGE RULE CREATED USING THE IBM SPECTRUM PROTECT OPERATIONS | |
| 3 | IT44479 5698ISMSV 81W | TASKS FOR A SERVER THAT NO LONGER EXISTS KEEPS APPEARING IN THE OPERATIONS CENTER MAINTENANCE VIEW | |
| 3 | IT45349 5698ISMSV 81A | NONEMPTY DECOMMISSIONED FILESPACES ARE REMOVED FROM SUBRULE MEMB ERS DURING EXPIRATION | |
| 4 | IT45983 5698ISMSV 81L | MISLEADING ANR2886E STORAGE RULE | |
| 2 | IT46141 5698ISMSV 81A | IBM STORAGE PROTECT SERVER CRASH, MUTEX ACQUISITION FAILURE | |
| 3 | IT46554 5698ISMSV 81L | REMOVE REPLNODE, DELETE SERVER AND REMOVE REPLSERVER COMMANDS DON'T REMOVE ENTRIES FROM DB2 REPLICATED_FILESPACES TABLE | |
| 2 | IT47640 5698ISMSV 81L | DELETE STORAGE POOL CAN GENERATE A LOT OF ANR9999D_2513553707 ERRORS | |
| 3 | IT47915 5698ISMSV 81A | ANR3002E NOTIFY SUBSCRIBERS: PROFILE NAME EXCEEDS 30 CHARACTERS | |
| 2 | IT47945 5698ISMSV 81L | DSMICFGX CREATES UNUSED TSM.PWD FILE | |
| 3 | IT47980 5698ISMSV 81L | REPLICATION FAILS WITH ANR3178E AND ANR0479W WHEN A COPY GROUP IS MISSING | |
| 3 | IT48205 5698ISMSV 81A | ANR4397E/ANR0454E STORAGE AGENT COMMUNICATION PROBLEM WHEN PASSW ORDS CONTAIN SPECIAL CHARACTERS | |
| 2 | IT48225 5698ISMSV 81A | MISSING DSMULOG BINARY IN IBM STORAGE PROTECT INSTALLATION PACKAGE FOR AIX STORAGE AGENT | |
| 2 | IT48246 5698ISMSV 81W | SERVER COULD CRASH WHEN RUNNING WITH THE REPLCMD TRACE FLAG ENABLED | |
| 2 | IT48310 5698ISMSV 81L | REPLICATION STORAGE RULE HANGS AND LEAVES SESSIONS ON TARGET SERVER | |
| 3 | IT48320 5698ISMSV 81L | PROTECT STGPOOL TYPE=LOCAL PROCESS HANGING AFTER UPGRADE TO 8.1.27.000 SERVER VERSION | |
| 3 | IT48341 5698ISMSV 81L | WHEN USING HOST-STYLE CLOUD CONNECTION CONFIGURATION, ORPHAN CLO UD CONTAINER OBJECTS REMAINED AFTER UPGRADING TO 8.1.18 SERVER | |
| 1 | IT48342 5698ISMSV 81W | DISMOUNT OF A NEWLY USED SCRATCH TAPE FAILS WITH ANR8355E I/O ER ROR READING LABEL USING 8.1.27 SERVER | |
| 3 | IT48344 5698ISMSV 81X | MKEYTOOL ERRORS OUT WHEN ADDING CA CERTIFICATES - JAVA.LANG.EXCEP TION: ALIAS | |
| 2 | IT48386 5698ISMSV 81A | (Reoccurrence of APAR IT44913) - IBM STORAGE PROTECT TARGET SERVER MAY CRASH DURING REPLICATION S TORAGE RULE, WITH SEGMENTATION FAULT | |
| 1 | IT48422 5698ISMSV 81L | COPY STORAGE RULE PERFORMANCE IS SLOW AFTER UPGRADING TO SERVER VERSION 8.1.27.000 | |
| 4 | IT48452 5698ISMSV 81A | ANR9759W MESSAGE NEEDS IMPROVEMENT WHEN A DRIVE SLOT IS EMPTY | |
| 2 | IT48471 5698ISMSV 81L | OFFSITE SPACE RECLAMATION FAILS WITH ANR9999D_0222697149 BFTESTOFFSITEMOVEFILE ERRORS | |
| 2 | IT48501 5698ISMSV 81L | IBM STORAGE PROTECT SERVER HALTS AFTER ANR0130E MESSAGE DUE TO REORG OF LARGE TABLES | |
| 2 | IT48516 5698ISMSV 81A | IBM STORAGE PROTECT SERVER CAN CRASH WHILE RUNNING EXPIRATION WHEN MEMORY IS NOT AVAILABLE | |
| 3 | IT48527 5698ISMSV 81L | THE ACTIVELOGSIZE VALUE IN DSMSERV.OPT MAY DIFFER FROM THE VALUE SHOWN IN QUERY OPTION | |
| 1 | IT48547 5698ISMSV 81A | UNEXPECTED DELETION ON A REPLICATION TARGET WITH LONGER DISSIMILAR POLICY AFTER THE REPLICATION IS DONE WITH FORCERECONCILE=YES | |
| 3 | IT48567 5698ISMSV 81L | IBM STORAGE PROTECT SERVER 8.1.27 ANR8507W MESSAGE IMPROPERLY RAISED IF DRIVEENCRYPTION IS SET TO OFF | |
| 4 | IT48587 5698ISMSV 81L | OUTDATED DOCUMENT FOR RECOVERING THE KEYSTORE'S PASSWORD | |
| 3 | IT48590 5698ISMSV 81L | SERVER UPGRADE MAY LOG "ERROR: ... GSKIT NOT FOUND ON SYSTEM" | |
| 1 | IT48644 5698ISMSV 81L | OPEN SNAP STORE MANAGER (OSSM) PRIMARY AGENT PANIC AFTER UPGRADE TO 8.1.27 | |
| 4 | IT48648 5698ISMSV 81L | DOCUMENTATION REQUEST FOR FILETEXTEXIT FORMAT IN IBM STORAGE PRO TECT 8.1.X |
Security vulnerabilities fixed in level 8.2.0.000
Security vulnerability | Abstract |
IBM Storage Protect Server use Golang glog library in OSSM component. Golang glog is vulnerable to improper handling of log file existence. | |
IBM Storage Protect Server, which uses IBM Db2, may be affected by multiple vulnerabilities that could result in denial of service or the loss of confidentiality, integrity. | |
IBM Storage Protect Server use Golang CoreDNS library in Object Agent and OSSM component. Golang coredns is vulnerable to Denial of Service. | |
IBM Storage Protect Server use Golang crypto library in Object Agent and OSSM component. Golang crypto is vulnerable to Denial of Service. | |
IBM Storage Protect Server use Golang net library in Object Agent and OSSM component. Golang net is vulnerable to IPv6 zone ID mishandling leading to proxy bypass. | |
IBM SDK, Java is vulnerable to improper access control and stack overflow, IBM Storage Protect Server uses IBM SDK, Java and may be affected by this vulnerability. | |
IBM Storage Protect Server use Golang CoreDNS library in Object Agent and OSSM component. Golang CoreDNS library is vulnerable to a denial of service, caused by improper input validation. | |
IBM SDK, Java is vulnerable to unauthenticated attacker with network access via multiple protocols and TLS, IBM Storage Protect Server uses IBM SDK, Java and may be affected by this vulnerability. |
APARs fixed in level 8.2.1.000
APAR | Severity | Operating System/Release Of Reported Issue (APAR, CompId, Rel) | Abstract |
| 3 | IT44363 5698ISMSV 81L | EXPIRATION PROCESS SKIPS EXPIRED OBJECTS WHICH ARE REPLICATED BY STORAGE RULE CREATED USING THE IBM SPECTRUM PROTECT OPERATIONS | |
| 2 | IT45220 5698ISMSV 81W | DELETE FILESPACE COMMAND FAILS AND INCORRECTLY DISPLAYS ANR0210W AND ANR0104E | |
| 3 | IT45349 5698ISMSV 81A | NONEMPTY DECOMMISSIONED FILESPACES ARE REMOVED FROM SUBRULE MEMBERS DURING EXPIRATION | |
| 2 | IT46270 5698ISMSV 81A | PROCESS APPARENT HANG WHEN QUERYING/USING STORAGE POOL WITH VIRTUAL VOLUMES | |
| 3 | IT46554 5698ISMSV 81L | REMOVE REPLNODE, DELETE SERVER AND REMOVE REPLSERVER COMMANDS DON'T REMOVE ENTRIES FROM DB2 REPLICATED_FILESPACES TABLE | |
| 2 | IT46866 5698ISMSV 81A | IBM STORAGE PROTECT TARGET SERVER MAY CRASH WHEN REPLRECOVERDAMAGED IS SET TO ON | |
| 3 | IT46909 5698ISMSV 81W | QUERY JOB COMMAND REPORTS INCORRECT REPLICATION PROCESS STATUS UNDER CERTAIN SCENARIOS | |
| 2 | IT47640 5698ISMSV 81L | DELETE STORAGE POOL CAN GENERATE A LOT OF ANR9999D_2513553707 ERRORS | |
| 3 | IT47899 5698ISMSV 81W | UNABLE TO UPDATE STORAGE PROTECT SERVERMON OUTPUT LOCATION | |
| 3 | IT47980 5698ISMSV 81L | REPLICATION FAILS WITH ANR3178E AND ANR0479W WHEN A COPY GROUP IS MISSING | |
| 2 | IT48064 5698ISMSV 81L | USING DELETE VOLHIST COMMAND TO DELETE DB BACKUP VOLUMES FROM CLOUD MAY LEAVE ORPHANED OBJECTS | |
| 3 | IT48424 5698ISMSV 81L | ANR1650W MESSAGE DISPLAYED IN ACTIVITY LOG WHEN RECENT REPLICATION COMPLETES SUCCESSFULLY WITHOUT REPORTING ANY ERRORS/WARNINGS | |
| 1 | IT48547 5698ISMSV 81A | UNEXPECTED DELETION ON A REPLICATION TARGET WITH LONGER DISSIMILAR POLICY AFTER THE REPLICATION IS DONE WITH FORCERECONCILE=YES | |
| 3 | IT48590 5698ISMSV 81L | SERVER UPGRADE MAY LOG "ERROR: ... GSKIT NOT FOUND ON SYSTEM" | |
| 3 | IT48603 5698ISMSV 81W | VERSION MISMATCH BETWEEN IBM INSTALLATION MANAGER AND WINDOWS "PROGRAM AND FEATURES" OUTPUT FOR SERVER LICENSE | |
| 1 | IT48644 5698ISMSV 81L | OPEN SNAP STORE MANAGER (OSSM) PRIMARY AGENT PANIC AFTER UPGRADE TO 8.1.27 | |
| 2 | IT48682 5698ISMSV 81A | IBM STORAGE PROTECT SERVER TARGET SERVER CRASHES DURING STGRULE FOR REPLICATION, DUE TO GSK ISSUE | |
| 2 | IT48681 5698ISMSV 81A | IBM STORAGE PROTECT SERVER TARGET SERVER CRASHES DURING STGRULE FOR REPLICATION, STACK POINTS TO MALLOC_Y | |
| 2 | IT48156 5698ISMSV 81L | OPERATIONS CENTER CLIENT UPDATES MISSING ELIGIBLE CANDIDATES AFTER UPGRADE TO 8.1.26 | |
| 3 | IT48826 5698ISMSV 81L | DOCUMENTATION ABOUT SET DRMPRIMSTGPOOL NEEDS IMPROVEMENTS | |
| 3 | IT48865 5698ISMSV 81A | REPLICATION COMPATIBILITY IS NOT UPDATED SINCE SERVER VERSION 8.1.17 | |
| 3 | IT48897 5698ISMSV 81A | DSMULOG DOCUMENTATION REQUIRES IMPROVEMENTS | |
| 3 | IT48906 5698ISMSV 81L | THE IBM STORAGE PROTECT SERVER MAY CRASH WHEN EXECUTING THE TIERING STORAGE POOL PROCESS | |
| 3 | IT48953 5698ISMSV 81A | OBSOLETE DOCUMENTATION REFERENCE TO THE MESSAGE - DO YOU WANT TO UPDATE THIS INSTANCE? ON HACMP SECONDARY NODE UPGRADE | |
| 3 | IT48954 5698ISMSV 81L | ANR9999D_3402937811 OCCURS WHEN LIBRARY CLIENTS UNABLE TO LOCATE EMPTY TAPE HOME POSITION WITH DRIVEENCRYPTION ENABLED | |
| 1 | IT48964 5698ISMSV 81L | OPERATIONS CENTER USERS WITH STATUSMONITIOR ENABLED MAY RUN INTO ISSUE WITH THE SERVER ACTIVELOG FULL |
Security vulnerabilities fixed in level 8.2.1.000
Security vulnerability | Abstract |
IBM Storage Protect Server uses the Eclipse Jetty web server library in certain components; Jetty is vulnerable to improper handling of malformed gzip requests that may lead to request data corruption or leakage between sessions. | |
IBM Storage Protect Server uses the Eclipse Jetty web server library in certain components; Eclipse Jetty web server library is vulnerable to issues in certificate and protocol handling that could lead to denial-of-service. | |
IBM Storage Protect Server uses the Apache Commons IO library in certain components; Apache Commons IO is vulnerable to improper resource handling that may lead to denial-of-service when processing specially crafted input. | |
IBM Storage Protect Server uses the Golang crypto library in Object Agent and OSSM component. Golang crypto is vulnerable to Denial of Service. | |
IBM Storage Protect Server provides a JSON-RPC endpoint through which authenticated users can execute backend SQL SELECT queries and access data from internal database tables, potentially exposing administrative metadata. | |
IBM Storage Protect Server uses the logback-core library in certain components; the library is vulnerable to improper handling of certain inputs that could lead to denial-of-service under specific conditions. | |
CVE-2025-50106, CVE-2025-30749, CVE-2025-30761, CVE-2025-30754 | IBM SDK, Java Technology Edition Quarterly CPU - July 2025 - Includes Oracle July 2025 CPU. |
IBM Storage Protect Server uses the logback-core library in certain components; the library is affected by an input handling flaw that could allow specially crafted inputs to trigger a denial-of-service condition. | |
CVE-2026-21945, CVE-2026-21932, CVE-2026-21933, CVE-2026-21925 | IBM SDK, Java Technology Edition Quarterly CPU - Jan 2026 - Includes Oracle January 2026 CPU. |
APARs fixed in level 8.2.1.200
APAR / KI | Severity | Operating System/Release Of Reported Issue (APAR, CompId, Rel) | Abstract |
| IT48808 | 2 | IT48808 5698ISMSV 81W | IT48808 ANR9999D_1038905726 DBIDBSPACESTATS(RDBDB.C:3885)THREAD<185>: RC 2343 FROM RDBEXECUTESQLTOSTRINGS. |
| 2 | IT46270 5698ISMSV 82L | CLOUD CONTAINERS REMAIN IN AN UNAVAILABLE STATE DESPITE ZERO DAMAGED EXTENTS. | |
| 2 | IT46554 5698ISMSV 81L | ANR3716E REPORTED AFTER UPGRADING TO 8.2.1 WITH MICROSOFT AZURE CLOUD CONNECTION | |
| DT470026 | 2 | DT470026 5698ISMSV 82L | CLOUD CONTAINERS BECOME UNAVAILABLE AND ARE INCORRECTLY MARKED AS DAMAGED AFTER UPGRADING THE IBM STORAGE PROTECT SERVER TO VERSION 8.2.1 |
| DT468065 | 1 | DT468065 5698ISMSV 82L | IBM STORAGE PROTECT SERVER DATABASE BACKUP TO GOOGLE CLOUD FAILS AFTER UPGRADING TO VERSION 8.2.1 |
| IT44044 | 2 | IT44044 5698ISMSV 81W | SPECTRUM PROTECT TARGET SERVER CRASH DURING REPLICATION STGRULE. |
| DT47090 | 3 | DT47090 5698ISMSV 82L | IF THE AIX MULTIHEAP SETTING IS CONFIGURED TOO LOW, IBM STORAGE PROTECT SERVERS MAY BECOME UNSTABLE, RESULTING IN HANGS OR CRASHES. |
| DT468247 | 2 | DT468247 5698ISMSV 82L | REPLICATION STGRULE MIGHT END WITH FAILURE DUE TO DATABASE DEADLOCK ON TARGET SERVER |
| DT469187 | 4 | DT469187 5698ISMSV 82L | THE IBM STORAGE PROTECT SERVER ‘INSTALL.SH’ SCRIPT NEEDS TO ACCEPT THE "-SKIPUPGRADECHECK" ARGUMENT |
| DT469333 | 2 | DT469333 5698ISMSV 82L | AFTER UPGRADING IBM STORAGE PROTECT OPERATIONS CENTER TO VERSION 8.2.1, THE SERVER MAINTENANCE TASKS ARE NO LONGER VISIBLE IN THE SERVER MAINTENANCE WINDOW. |
Security vulnerabilities fixed in level 8.2.1.200
Security vulnerability | Abstract |
IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow denial of service, memory exhaustion, privilege escalation, improper authentication handling, or exposure of sensitive information under specific conditions. | |
IBM Storage Protect Server uses the IBM Db2 database for certain components; Db2 contains multiple vulnerabilities that may allow service disruption, memory handling flaws, unauthorized privilege elevation, insufficient input sanitization, authentication-related weaknesses, and excessive resource consumption. | |
CVE-2025-36247, CVE-2025-36425, CVE-2025-13867, CVE-2025-14689 | IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow improper input handling, memory management weaknesses, and security control bypass conditions that could lead to service instability, denial of service, or unintended access under specific circumstances. |
IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow improper input handling, memory management flaws, authentication weaknesses, privilege escalation, and denial-of-service conditions. |
APARs fixed in level 8.2.2.000
APAR / KI | Severity | Operating System/Release Of Reported Issue (APAR, CompId, Rel) | Abstract |
| 3 | IT45739 5698ISMSV 81L | ANR1652E MAY OCCUR AFTER REMOVE REPLNODE AND UPDATE NODE REPLSTATE=ENABLED. | |
| 2 | IT48217 5698ISMSV 82L | DELETE CONTAINER STORAGE POOL DOES NOT FREE UP SPACE | |
| 3 | IT48324 5698ISMSV 82L | REMOVE THE MOVE DATA RESTRICTION FOR TAPE LOCATED IN THE NEXTSTG POOL FOR A COLDDATACACHE STGPOOL | |
| 3 | IT48429 5698ISMSV 82L | DISK STORAGE POOL PCT MIGR IS HIGHER THAN PCT UTIL AFTER THE MIGRATION PROCESS | |
| 2 | IT48453 5698ISMSV 82L | TIERING PROCESS COMPLETED SUCCESSFULLY WITHOUT TIERING ALL DATA WHEN USING TIER BY AGE = 0 | |
| 2 | IT48727 5698ISMSV 82L | CRASH OF DSMSERV PROCESS DURING SERVERMONTENMINTHREAD EXECUTION OF QUERY PROCESS | |
| 2 | IT48808 5698ISMSV 81W | ANR9999D_1038905726 DBIDBSPACESTATS(RDBDB.C:3885)THREAD<185>: RC 2343 FROM RDBEXECUTESQLTOSTRINGS. | |
| 1 | IT48905 5698ISMSV 82L | IBM STORAGE PROTECT PLUS REPLICATION JOB OVER OSSM FAILING IF REPLICATION STARTED IMMEDIATELY AFTER SUCCESSFUL BACKUP | |
| 3 | IT48957 5698ISMSV 82L | QUERY DBSPACE DOES NOT REPORT USED SPACE ON FILESYSTEM CORRECTLY WHEN DIRECTORIES USE SAME FILESYSTEM/DRIVE | |
| 2 | IT49035 5698ISMSV 82L | MISSING WARNING ON AUDIT LIBRARY COMMAND WITH TYPE SHARED IN MULTI-LIBRARY MANAGER/CLIENT ENVIRONMENTS. | |
| 4 | IT49065 5698ISMSV 82L | AUDIT LIBRARY FINISHES SUCCESSFULLY WHEN ERRORS AND WARNINGS ARE REPORTED | |
| 3 | IT49064 5698ISMSV 82L | AUDIT LIBVOLUME DOES NOT COMPARE THE BARCODE WITH THE INTERNAL LABEL | |
| DT468772 5698ISMSV 82L | UNEXPECTED DIFFERENT DEDUPLICATION AND COMPRESSION SAVINGS BETWEEN SOURCE AND TARGET IBM STORAGE PROTECT SERVERS POOLS | ||
| DT469333 5698ISMSV 82L | AFTER UPGRADING IBM STORAGE PROTECT OPERATIONS CENTER TO VERSION 8.2.1, THE SERVER MAINTENANCE TASKS ARE NO LONGER VISIBLE IN THE SERVER MAINTENANCE WINDOW. | ||
| DT468897 5698ISMSV 82L | UNABLE TO DELETE FILESPACE IF IT HAD DATA IN A RETENTION SET THAT IS DELETED BEFORE IT EXPIRES NATURALLY | ||
| DT469894 5698ISMSV 82L | INCORRECT CATEGORY FOR TOTAL POOL RESERVATION NEGATIVE (XX, YY) MESSAGE IN TARGET SERVER DSMFFDC LOG DURING REPLICATION. | ||
| DT467700 5698ISMSV 82L | ANR8944E KEY/ASC/ASCQ 04/44/00 SENSE CODE DOES NOT PLACE DRIVE OFFLINE | ||
| DT470400 5698ISMSV 82L | CLOUD CONTAINERS REMAIN IN AN UNAVAILABLE STATE DESPITE ZERO DAMAGED EXTENTS | ||
| DT469732 5698ISMSV 81L | ANR3716E A REQUEST TO THE AZURE CLOUD SERVICE PROVIDER FOR THE WRITE OBJECT OPERATION ON THE CLOUD-CONNECTION OR STORAGE POOL FAILED WITH THE FOLLOWING HTTP STATUS CODE: 409. | ||
| DT470905 5698ISMSV 82L | IBM STORAGE PROTECT SERVER ON AIX REQUIRES THE MULTIHEAP PARAMETER TO BE SET TO 16 (MULTIHEAP:16). THIS REQUIREMENT IS DOCUMENTED IN BOTH THE BLUEPRINT AND THE AIX INSTALLATION GUIDE. | ||
| DT469187 5698ISMSV 82L | DISABLE -SKIPUPGRADECHECK FLAG FOR SILENT INSTALLATION USING INSTALLATION MANAGER | ||
| 4 | IT48250 5698ISMSV 82L | AFTER ADDING NEW DATA COLLECTION COMMANDS INTO COMMAND.INI FILE, THE COMMANDS ARE NOT RUN | |
| DT468124 5698ISMSV 82L | MISSING CLOSING QUOTATION MARK IN OPERATIONS CENTER NON-ROOT STARTUP DOCUMENTATION FOR LINUX | ||
| DT474942 5698ISMSV 82L | IBM OPERATIONS CENTER (OC) – CLIENTS ELIGIBLE FOR DEPLOYMENT ON SPOKE SERVERS, SOMETIMES NOT SHOWING UP AS CANDIDATE | ||
| DT474187 5698ISMSV 82L | ANR1631I MESSAGE REPLICATION STATE INFORMATION FOR THE SPECIFIED NODES HAVE BEEN REMOVED USES THE WORD HAVE INCORRECTLY | ||
| 2 | IT49015 5698ISMSV 82L | UPDATE AUDIT LIBRARY COMMAND IN IBM STORAGE PROTECT DOCUMENTATION | |
| 3 | IT48994 5698ISMSV 82L | INCOMPLETE DOCUMENTATION FOR TOTAL FILE SIZES IN QUERY RESULT SET OUTPUT | |
| 2 | IT49081 5698ISMSV 82L | REPAIR STGPOOL COMMAND HANGS WITH WAIT=YES AND PREVIEW=YES WHEN STGRULE REPLICATION IS SET ON THE POOL. | |
| 4 | IT48933 5698ISMSV 82L | UNDOCUMENTED FIELDS ENCRYPTED, COMPRESSED, AND COMPRESSED CAPACITY IN QUERY VOLUME | |
| 3 | IT48252 5698ISMSV 82L | THE SERVERMON DATA COLLECTION MAY NOT COLLECT DSMFFDC LOGS | |
| 2 | IT48166 5698ISMSV 82L | THE 'SERVERMON -STOP -FORCE' COMMAND MIGHT LEAVE A <DEFUNCT> PROCESS | |
| DT473958 5698ISMSV 82L | DISABLEREORGTABLE MANUAL PAGE SHOULD LIST ALL TABLES EXCLUDED FROM TABLE REORGANIZATION BY DEFAULT | ||
| 3 | IT45947 5698ISMSV 82L | USING AWS VIRTUAL-HOSTED-STYLE URL RESULTS IN ORPHANED RETENTION SET COPY VOLUMES | |
| DT468065 5698ISMSV 82L | IBM STORAGE PROTECT SERVER DATABASE BACKUP TO GOOGLE CLOUD FAILS AFTER UPGRADING TO VERSION 8.2.1 | ||
| DT468229 5698ISMSV 82L | ANR2337W AND ANR2338E CAN BE SEEN WHEN THERE IS A MIX OF LBP AND NON-LBP DATA BLOCKS ON TAPE | ||
| DT469011 5698ISMSV 82L | UNEXPECTED MESSAGE ANR3658E WHEN NO PROTECT STGPOOL PROCESS IS ACTIVE | ||
| DT468247 5698ISMSV 82L | REPLICATION STGRULE MIGHT END WITH FAILURE DUE TO DATABASE DEADLOCK ON TARGET SERVER | ||
| DT470026 5698ISMSV 82L | CLOUD CONTAINERS BECOME UNAVAILABLE AND ARE INCORRECTLY MARKED AS DAMAGED AFTER UPGRADING THE IBM STORAGE PROTECT SERVER TO VERSION 8.2.1 | ||
| DT468813 5698ISMSV 82L | IBM OPERATIONS CENTER (OC) CUSTOM REPORT - "SERVER" SELECTION MAY AUTOMATICALLY INCLUDE SERVER(S) WITH SIMILAR NAME | ||
| DT467792 5698ISMSV 82L | IBM STORAGE PROTECT SERVERMON FAILS TO START ON AIX 7.3 TL4 POST UPGRADE | ||
| DT471296 5698ISMSV 82L | AFTER UPGRADING OPERATIONS CENTER TO VERSION 8.2.1 THE STATUS LINKS DO NOT OPEN |
Security vulnerabilities fixed in level 8.2.2.000
Security vulnerability | Abstract |
IBM Storage Protect Server uses the Eclipse Jersey Client library in certain components; Eclipse Jersey Client is vulnerable to a race condition that may lead to SSL/TLS security configurations issues. | |
IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow denial of service, memory exhaustion, privilege escalation, improper authentication handling, or exposure of sensitive information under specific conditions. | |
IBM Storage Protect Server uses the IBM Db2 database for certain components; Db2 contains multiple vulnerabilities that may allow service disruption, memory handling flaws, unauthorized privilege elevation, insufficient input sanitization, authentication-related weaknesses, and excessive resource consumption. | |
CVE-2025-36247, CVE-2025-36425, CVE-2025-13867, CVE-2025-14689 | IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow improper input handling, memory management weaknesses, and security control bypass conditions that could lead to service instability, denial of service, or unintended access under specific circumstances. |
IBM Storage Protect Server uses the Eclipse http2-common library in certain components; Eclipse http2-common library may allow a remote attacker to trigger denial-of-service conditions through specially crafted HTTP/2 requests. | |
IBM Storage Protect Server uses the netty library in certain components; netty library may allow remote attacker to craft malicious HTTP requests to bypass intermediary parsing logic and inject unintended requests into backend connections, potentially impacting application integrity and security. | |
IBM Storage Protect Server uses the netty library in certain components; netty library may allow improper handling of HTTP protocol processing under specific malformed request conditions. | |
IBM Storage Protect Server uses the Eclipse Jetty web server library in certain components; Jetty may cause improper cleanup of ThreadLocal authentication data during request processing. | |
IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow improper input handling, memory management flaws, authentication weaknesses, privilege escalation, and denial-of-service conditions. | |
IBM Storage Protect Server uses the Eclipse Jetty web server library in certain components; Eclipse Jetty web server library may allow remote attacker to craft malicious HTTP requests to smuggle unintended backend requests, potentially leading to cache poisoning, access-control bypass, or request injection attacks. | |
IBM Storage Protect Server uses the netty library in certain components; netty library may allow improper handling of network protocol processing and buffer management under specific malformed input conditions. | |
IBM Storage Protect Server uses the netty library in certain components; netty library may allow improper validation and handling of specially crafted network input during protocol processing. | |
CVE-2026-42580, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42587 | IBM Storage Protect Server uses the netty library in certain components; netty library is affected by multiple vulnerabilities which may allow improper protocol handling, insufficient input validation, and resource management weaknesses when processing specially crafted network requests. |
IBM Storage Protect Server uses the netty library in certain components; netty library may allow insufficient validation and processing of maliciously crafted network requests during protocol handling. | |
IBM Storage Protect Server uses the Golang sys library in OSSM and ObjectAgent component. Golang sys is vulnerable to data integrity issues. | |
IBM Storage Protect Server uses the Golang crypto library in OSSM and ObjectAgent component. Golang crypto has multiple vulnerabilities that may cause denial of service, authentication and certificate validation bypasses or resource exhaustion. | |
CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-42502, CVE-2026-42506 | IBM Storage Protect Server uses the Golang net library in OSSM and ObjectAgent component. Golang net has multiple vulnerabilities that may cause input validation bypasses, and other unintended application behaviors through specially crafted network requests. |
Was this topic helpful?
Document Information
Modified date:
31 July 2026
UID
ibm17253222