IBM Support

APARs fixed in the IBM Storage Protect Server Version 8.2 levels

Fix Readme


Abstract

What APARs and security fixes have been incorporated in the IBM Storage Protect server Version 8.2 levels?

Content

The following tables list APARs that are addressed in the IBM Storage Protect server V8.2 levels.  

Tip: In the following list, Rel represents the release number in which the issue was detected. The operating system is identified (A = AIX, L = Linux, and W = Windows). For example, 82L denotes V8.2 running on a Linux operating system.

APARs fixed in level 8.2.0.000
Security vulnerabilities fixed in level 8.2.0.000  
APARs fixed in level 8.2.1.000  
Security vulnerabilities fixed in level 8.2.1.000  
APARs fixed in level 8.2.1.200  
Security vulnerabilities fixed in level 8.2.1.200
APARs fixed in level 8.2.2.000  
Security vulnerabilities fixed in level 8.2.2.000  
 

APARs fixed in level 8.2.0.000

APAR
Severity
Operating System/Release  
Of Reported Issue  
(APAR, CompId, Rel)
Abstract

IT42602

4IT42602 5698ISMSV 81LQUERY REPLNODE WITH A SPECIFIC SERVER STILL SHOWS UP AFTER REMOVE REPLNODE

IT44363

3IT44363 5698ISMSV 81L

EXPIRATION PROCESS SKIPS EXPIRED OBJECTS WHICH ARE REPLICATED BY STORAGE RULE CREATED USING THE IBM SPECTRUM PROTECT OPERATIONS

IT44479

3IT44479 5698ISMSV 81W

TASKS FOR A SERVER THAT NO LONGER EXISTS KEEPS APPEARING IN THE OPERATIONS CENTER MAINTENANCE VIEW

IT45349

3IT45349 5698ISMSV 81A

NONEMPTY DECOMMISSIONED FILESPACES ARE REMOVED FROM SUBRULE MEMB ERS DURING EXPIRATION

IT45983

4IT45983 5698ISMSV 81L

MISLEADING ANR2886E STORAGE RULE  WAS NOT FOUND ON REPLICATION STORAGE RULE START WHILE IT IS CORRECTLY DEFINED

IT46141

2IT46141 5698ISMSV 81A

IBM STORAGE PROTECT SERVER CRASH, MUTEX ACQUISITION FAILURE

IT46554

3IT46554 5698ISMSV 81L

REMOVE REPLNODE, DELETE SERVER AND REMOVE REPLSERVER COMMANDS DON'T REMOVE ENTRIES FROM DB2 REPLICATED_FILESPACES TABLE

IT47640

2IT47640 5698ISMSV 81L

DELETE STORAGE POOL CAN GENERATE A LOT OF ANR9999D_2513553707 ERRORS

IT47915

3IT47915 5698ISMSV 81A

ANR3002E NOTIFY SUBSCRIBERS: PROFILE NAME EXCEEDS 30 CHARACTERS

IT47945

2IT47945 5698ISMSV 81L

DSMICFGX CREATES UNUSED TSM.PWD FILE

IT47980

3IT47980 5698ISMSV 81L

REPLICATION FAILS WITH ANR3178E AND ANR0479W WHEN A COPY GROUP IS MISSING

IT48205

3IT48205 5698ISMSV 81A

ANR4397E/ANR0454E STORAGE AGENT COMMUNICATION PROBLEM WHEN PASSW ORDS CONTAIN SPECIAL CHARACTERS

IT48225

2IT48225 5698ISMSV 81A

MISSING DSMULOG BINARY IN IBM STORAGE PROTECT INSTALLATION PACKAGE FOR AIX STORAGE AGENT

IT48246

2IT48246 5698ISMSV 81W

SERVER COULD CRASH WHEN RUNNING WITH THE REPLCMD TRACE FLAG ENABLED

IT48310

2IT48310 5698ISMSV 81L

REPLICATION STORAGE RULE HANGS AND LEAVES SESSIONS ON TARGET SERVER

IT48320

3IT48320 5698ISMSV 81L

PROTECT STGPOOL TYPE=LOCAL PROCESS HANGING AFTER UPGRADE TO 8.1.27.000 SERVER VERSION

IT48341

3IT48341 5698ISMSV 81L

WHEN USING HOST-STYLE CLOUD CONNECTION CONFIGURATION, ORPHAN CLO UD CONTAINER OBJECTS REMAINED AFTER UPGRADING TO 8.1.18 SERVER

IT48342

1IT48342 5698ISMSV 81W

DISMOUNT OF A NEWLY USED SCRATCH TAPE FAILS WITH ANR8355E I/O ER ROR READING LABEL USING 8.1.27 SERVER

IT48344

3IT48344 5698ISMSV 81X

MKEYTOOL ERRORS OUT WHEN ADDING CA CERTIFICATES - JAVA.LANG.EXCEP TION: ALIAS  DOES NOT EXIST

IT48386

2IT48386 5698ISMSV 81A

(Reoccurrence of APAR IT44913) - IBM STORAGE PROTECT TARGET SERVER MAY CRASH DURING REPLICATION S TORAGE RULE, WITH SEGMENTATION FAULT

IT48422

1IT48422 5698ISMSV 81L

COPY STORAGE RULE PERFORMANCE IS SLOW AFTER UPGRADING TO SERVER VERSION 8.1.27.000

IT48452

4IT48452 5698ISMSV 81A

ANR9759W MESSAGE NEEDS IMPROVEMENT WHEN A DRIVE SLOT IS EMPTY

IT48471

2IT48471 5698ISMSV 81L

OFFSITE SPACE RECLAMATION FAILS WITH ANR9999D_0222697149 BFTESTOFFSITEMOVEFILE ERRORS

IT48501

2IT48501 5698ISMSV 81L

IBM STORAGE PROTECT SERVER HALTS AFTER ANR0130E MESSAGE DUE TO REORG OF LARGE TABLES

IT48516

2IT48516 5698ISMSV 81A

IBM STORAGE PROTECT SERVER CAN CRASH WHILE RUNNING EXPIRATION WHEN MEMORY IS NOT AVAILABLE

IT48527

3IT48527 5698ISMSV 81L

THE ACTIVELOGSIZE VALUE IN DSMSERV.OPT MAY DIFFER FROM THE VALUE SHOWN IN QUERY OPTION

IT48547

1IT48547 5698ISMSV 81A

UNEXPECTED DELETION ON A REPLICATION TARGET WITH LONGER DISSIMILAR POLICY AFTER THE REPLICATION IS DONE WITH FORCERECONCILE=YES

IT48567

3IT48567 5698ISMSV 81L

IBM STORAGE PROTECT SERVER 8.1.27 ANR8507W MESSAGE IMPROPERLY RAISED IF DRIVEENCRYPTION IS SET TO OFF

IT48587

4IT48587 5698ISMSV 81L

OUTDATED DOCUMENT FOR RECOVERING THE KEYSTORE'S PASSWORD

IT48590

3IT48590 5698ISMSV 81L

SERVER UPGRADE MAY LOG "ERROR: ... GSKIT NOT FOUND ON SYSTEM"

IT48644

1IT48644 5698ISMSV 81L

OPEN SNAP STORE MANAGER (OSSM) PRIMARY AGENT PANIC AFTER UPGRADE TO 8.1.27

IT48648

4IT48648 5698ISMSV 81L

DOCUMENTATION REQUEST FOR FILETEXTEXIT FORMAT IN IBM STORAGE PRO TECT 8.1.X

 

Security vulnerabilities fixed in level 8.2.0.000

Security vulnerability
Abstract

CVE-2024-45339

IBM Storage Protect Server use Golang glog library in OSSM component. Golang glog is vulnerable to improper handling of log file existence.

CVE-2024-7254, CVE-2022-3510, CVE-2022-3509, CVE-2022-3171, CVE-2024-49350, CVE-2025-3050, CVE-2025-2518, CVE-2024-52903, CVE-2025-1493, CVE-2025-1000, CVE-2025-1992, CVE-2025-0915

IBM Storage Protect Server, which uses IBM Db2, may be affected by multiple vulnerabilities that could result in denial of service or the loss of confidentiality, integrity.

CVE-2025-47950

IBM Storage Protect Server use Golang CoreDNS library in Object Agent and OSSM component. Golang coredns is vulnerable to Denial of Service.

CVE-2025-22869

IBM Storage Protect Server use Golang crypto library in Object Agent and OSSM component. Golang crypto is vulnerable to Denial of Service.

CVE-2025-22870

IBM Storage Protect Server use Golang net library in Object Agent and OSSM component. Golang net is vulnerable to IPv6 zone ID mishandling leading to proxy bypass.

CVE-2025-21587, CVE-2025-30698, CVE-2025-4447

IBM SDK, Java is vulnerable to improper access control and stack overflow, IBM Storage Protect Server uses IBM SDK, Java and may be affected by this vulnerability.

CVE-2025-58063

IBM Storage Protect Server use Golang CoreDNS library in Object Agent and OSSM component. Golang CoreDNS library is vulnerable to a denial of service, caused by improper input validation.

CVE-2025-50106, CVE-2025-30749

IBM SDK, Java is vulnerable to unauthenticated attacker with network access via multiple protocols and TLS, IBM Storage Protect Server uses IBM SDK, Java and may be affected by this vulnerability.

 

APARs fixed in level 8.2.1.000

APAR
Severity
Operating System/Release  
Of Reported Issue  
(APAR, CompId, Rel)
Abstract

IT44363

3IT44363 5698ISMSV 81LEXPIRATION PROCESS SKIPS EXPIRED OBJECTS WHICH ARE REPLICATED BY STORAGE RULE CREATED USING THE IBM SPECTRUM PROTECT OPERATIONS

IT45220

2IT45220 5698ISMSV 81WDELETE FILESPACE COMMAND FAILS AND INCORRECTLY DISPLAYS ANR0210W AND ANR0104E

IT45349

3IT45349 5698ISMSV 81ANONEMPTY DECOMMISSIONED FILESPACES ARE REMOVED FROM SUBRULE MEMBERS DURING EXPIRATION

IT46270

2IT46270 5698ISMSV 81APROCESS APPARENT HANG WHEN QUERYING/USING STORAGE POOL WITH VIRTUAL VOLUMES

IT46554

3IT46554 5698ISMSV 81LREMOVE REPLNODE, DELETE SERVER AND REMOVE REPLSERVER COMMANDS DON'T REMOVE ENTRIES FROM DB2 REPLICATED_FILESPACES TABLE

IT46866

2IT46866 5698ISMSV 81AIBM STORAGE PROTECT TARGET SERVER MAY CRASH WHEN REPLRECOVERDAMAGED IS SET TO ON

IT46909

3IT46909 5698ISMSV 81WQUERY JOB COMMAND REPORTS INCORRECT REPLICATION PROCESS STATUS UNDER CERTAIN SCENARIOS

IT47640

2IT47640 5698ISMSV 81LDELETE STORAGE POOL CAN GENERATE A LOT OF ANR9999D_2513553707 ERRORS

IT47899

3IT47899 5698ISMSV 81WUNABLE TO UPDATE STORAGE PROTECT SERVERMON OUTPUT LOCATION

IT47980

3IT47980 5698ISMSV 81LREPLICATION FAILS WITH ANR3178E AND ANR0479W WHEN A COPY GROUP IS MISSING

IT48064

2IT48064 5698ISMSV 81LUSING DELETE VOLHIST COMMAND TO DELETE DB BACKUP VOLUMES FROM CLOUD MAY LEAVE ORPHANED OBJECTS

IT48424

3IT48424 5698ISMSV 81LANR1650W MESSAGE DISPLAYED IN ACTIVITY LOG WHEN RECENT REPLICATION COMPLETES SUCCESSFULLY WITHOUT REPORTING ANY ERRORS/WARNINGS

IT48547

1IT48547 5698ISMSV 81AUNEXPECTED DELETION ON A REPLICATION TARGET WITH LONGER DISSIMILAR POLICY AFTER THE REPLICATION IS DONE WITH FORCERECONCILE=YES

IT48590

3IT48590 5698ISMSV 81LSERVER UPGRADE MAY LOG "ERROR: ... GSKIT NOT FOUND ON SYSTEM"

IT48603

3IT48603 5698ISMSV 81WVERSION MISMATCH BETWEEN IBM INSTALLATION MANAGER AND WINDOWS "PROGRAM AND FEATURES" OUTPUT FOR SERVER LICENSE

IT48644

1IT48644 5698ISMSV 81LOPEN SNAP STORE MANAGER (OSSM) PRIMARY AGENT PANIC AFTER UPGRADE TO 8.1.27

IT48682

2IT48682 5698ISMSV 81AIBM STORAGE PROTECT SERVER TARGET SERVER CRASHES DURING STGRULE FOR REPLICATION, DUE TO GSK ISSUE

IT48681

2IT48681 5698ISMSV 81AIBM STORAGE PROTECT SERVER TARGET SERVER CRASHES DURING STGRULE FOR REPLICATION, STACK POINTS TO MALLOC_Y

IT48156

2IT48156 5698ISMSV 81LOPERATIONS CENTER CLIENT UPDATES MISSING ELIGIBLE CANDIDATES AFTER UPGRADE TO 8.1.26

IT48826

3IT48826 5698ISMSV 81LDOCUMENTATION ABOUT SET DRMPRIMSTGPOOL NEEDS IMPROVEMENTS

IT48865

3IT48865 5698ISMSV 81AREPLICATION COMPATIBILITY IS NOT UPDATED SINCE SERVER VERSION 8.1.17

IT48897

3IT48897 5698ISMSV 81ADSMULOG DOCUMENTATION REQUIRES IMPROVEMENTS

IT48906

3IT48906 5698ISMSV 81LTHE IBM STORAGE PROTECT SERVER MAY CRASH WHEN EXECUTING THE TIERING STORAGE POOL PROCESS

IT48953

3IT48953 5698ISMSV 81AOBSOLETE DOCUMENTATION REFERENCE TO THE MESSAGE - DO YOU WANT TO UPDATE THIS INSTANCE? ON HACMP SECONDARY NODE UPGRADE

IT48954

3IT48954 5698ISMSV 81LANR9999D_3402937811 OCCURS WHEN LIBRARY CLIENTS UNABLE TO LOCATE EMPTY TAPE HOME POSITION WITH DRIVEENCRYPTION ENABLED

IT48964

1IT48964 5698ISMSV 81LOPERATIONS CENTER USERS WITH STATUSMONITIOR ENABLED MAY RUN INTO ISSUE WITH THE SERVER ACTIVELOG FULL

 

Security vulnerabilities fixed in level 8.2.1.000

Security vulnerability
Abstract

CVE-2024-13009

IBM Storage Protect Server uses the Eclipse Jetty web server library in certain components; Jetty is vulnerable to improper handling of malformed gzip requests that may lead to request data corruption or leakage between sessions.

CVE-2024-6763, CVE-2024-8184

IBM Storage Protect Server uses the Eclipse Jetty web server library in certain components; Eclipse Jetty web server library is vulnerable to issues in certificate and protocol handling that could lead to denial-of-service.

CVE-2025-48924

IBM Storage Protect Server uses the Apache Commons IO library in certain components; Apache Commons IO is vulnerable to improper resource handling that may lead to denial-of-service when processing specially crafted input.

CVE-2025-47913, CVE-2025-47914, CVE-2025-58181

IBM Storage Protect Server uses the Golang crypto library in Object Agent and OSSM component. Golang crypto is vulnerable to Denial of Service.

CVE-2025-13855

IBM Storage Protect Server provides a JSON-RPC endpoint through which authenticated users can execute backend SQL SELECT queries and access data from internal database tables, potentially exposing administrative metadata.

CVE-2025-11226

IBM Storage Protect Server uses the logback-core library in certain components; the library is vulnerable to improper handling of certain inputs that could lead to denial-of-service under specific conditions.

CVE-2025-50106, CVE-2025-30749, CVE-2025-30761, CVE-2025-30754

IBM SDK, Java Technology Edition Quarterly CPU - July 2025 - Includes Oracle July 2025 CPU.

CVE-2026-1225

IBM Storage Protect Server uses the logback-core library in certain components; the library is affected by an input handling flaw that could allow specially crafted inputs to trigger a denial-of-service condition.

CVE-2026-21945, CVE-2026-21932, CVE-2026-21933, CVE-2026-21925

IBM SDK, Java Technology Edition Quarterly CPU - Jan 2026 - Includes Oracle January 2026 CPU.

 

APARs fixed in level 8.2.1.200

APAR / KI
Severity
Operating System/Release  
Of Reported Issue  
(APAR, CompId, Rel)
Abstract
IT488082IT48808 5698ISMSV 81WIT48808 ANR9999D_1038905726 DBIDBSPACESTATS(RDBDB.C:3885)THREAD<185>: RC 2343 FROM RDBEXECUTESQLTOSTRINGS.

DT470400

2IT46270 5698ISMSV 82LCLOUD CONTAINERS REMAIN IN AN UNAVAILABLE STATE DESPITE ZERO DAMAGED EXTENTS.

DT469732

2IT46554 5698ISMSV 81LANR3716E REPORTED AFTER UPGRADING TO 8.2.1 WITH MICROSOFT AZURE CLOUD CONNECTION
DT4700262DT470026 5698ISMSV 82LCLOUD CONTAINERS BECOME UNAVAILABLE AND ARE INCORRECTLY MARKED AS DAMAGED AFTER UPGRADING THE IBM STORAGE PROTECT SERVER TO VERSION 8.2.1
DT4680651DT468065 5698ISMSV 82LIBM STORAGE PROTECT SERVER DATABASE BACKUP TO GOOGLE CLOUD FAILS AFTER UPGRADING TO VERSION 8.2.1
IT440442IT44044 5698ISMSV 81WSPECTRUM PROTECT TARGET SERVER CRASH DURING REPLICATION STGRULE.
DT470903DT47090 5698ISMSV 82LIF THE AIX MULTIHEAP SETTING IS CONFIGURED TOO LOW, IBM STORAGE PROTECT SERVERS MAY BECOME UNSTABLE, RESULTING IN HANGS OR CRASHES.
DT4682472DT468247 5698ISMSV 82LREPLICATION STGRULE MIGHT END WITH FAILURE DUE TO DATABASE DEADLOCK ON TARGET SERVER
DT4691874DT469187 5698ISMSV 82LTHE IBM STORAGE PROTECT SERVER ‘INSTALL.SH’ SCRIPT NEEDS TO ACCEPT THE "-SKIPUPGRADECHECK" ARGUMENT
DT4693332DT469333 5698ISMSV 82LAFTER UPGRADING IBM STORAGE PROTECT OPERATIONS CENTER TO VERSION 8.2.1, THE SERVER MAINTENANCE TASKS ARE NO LONGER VISIBLE IN THE SERVER MAINTENANCE WINDOW.

 

 

  Security vulnerabilities fixed in level 8.2.1.200

Security vulnerability
Abstract

CVE-2025-33012, CVE-2025-33134, CVE-2025-2534, CVE-2024-47118, CVE-2025-36006, CVE-2025-36008, CVE-2025-36131, CVE-2025-36136, CVE-2025-36186, CVE-2025-36185, CVE-2024-57699, 256137, 177835

IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow denial of service, memory exhaustion, privilege escalation, improper authentication handling, or exposure of sensitive information under specific conditions.

 CVE-2024-47072, CVE-2025-36442, CVE-2025-36428, CVE-2025-36427, CVE-2025-36424, CVE-2025-36407, CVE-2025-36387, CVE-2025-36366, CVE-2025-36384, CVE-2025-36365, CVE-2025-8916, CVE-2025-58056, CVE-2025-58057, CVE-2025-55163, CVE-2025-36353, CVE-2025-36098, CVE-2025-36123, CVE-2025-36070, CVE-2025-36009, CVE-2025-36001, CVE-2025-36184, CVE-2025-2668

IBM Storage Protect Server uses the IBM Db2 database for certain components; Db2 contains multiple vulnerabilities that may allow service disruption, memory handling flaws, unauthorized privilege elevation, insufficient input sanitization, authentication-related weaknesses, and excessive resource consumption.

CVE-2025-36247, CVE-2025-36425, CVE-2025-13867, CVE-2025-14689

IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow improper input handling, memory management weaknesses, and security control bypass conditions that could lead to service instability, denial of service, or unintended access under specific circumstances.

CVE-2025-36122, CVE-2025-14688, CVE-2025-67735, CVE-2025-68161, CVE-2025-12183, CVE-2026-1352, CVE-2026-1577, CVE-2026-3676

IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow improper input handling, memory management flaws, authentication weaknesses, privilege escalation, and denial-of-service conditions.

 

APARs fixed in level 8.2.2.000

APAR / KI
Severity
Operating System/Release  
Of Reported Issue  
(APAR, CompId, Rel)
Abstract

IT45739

3IT45739 5698ISMSV 81LANR1652E MAY OCCUR AFTER REMOVE REPLNODE AND UPDATE NODE REPLSTATE=ENABLED.

IT48217

2IT48217 5698ISMSV 82LDELETE CONTAINER STORAGE POOL DOES NOT FREE UP SPACE

IT48324

3IT48324 5698ISMSV 82LREMOVE THE MOVE DATA RESTRICTION FOR TAPE LOCATED IN THE NEXTSTG POOL FOR A COLDDATACACHE STGPOOL

IT48429

3IT48429 5698ISMSV 82LDISK STORAGE POOL PCT MIGR IS HIGHER THAN PCT UTIL AFTER THE MIGRATION PROCESS

IT48453

2IT48453 5698ISMSV 82LTIERING PROCESS COMPLETED SUCCESSFULLY WITHOUT TIERING ALL DATA WHEN USING TIER BY AGE = 0

IT48727

2IT48727 5698ISMSV 82LCRASH OF DSMSERV PROCESS DURING SERVERMONTENMINTHREAD EXECUTION OF QUERY PROCESS

IT48808

2IT48808 5698ISMSV 81WANR9999D_1038905726 DBIDBSPACESTATS(RDBDB.C:3885)THREAD<185>: RC 2343 FROM RDBEXECUTESQLTOSTRINGS.

IT48905

1IT48905 5698ISMSV 82LIBM STORAGE PROTECT PLUS REPLICATION JOB OVER OSSM FAILING IF REPLICATION STARTED IMMEDIATELY AFTER SUCCESSFUL BACKUP

IT48957

3IT48957 5698ISMSV 82LQUERY DBSPACE DOES NOT REPORT USED SPACE ON FILESYSTEM CORRECTLY WHEN DIRECTORIES USE SAME FILESYSTEM/DRIVE

IT49035

2IT49035 5698ISMSV 82LMISSING WARNING ON AUDIT LIBRARY COMMAND WITH TYPE SHARED IN MULTI-LIBRARY MANAGER/CLIENT ENVIRONMENTS.

IT49065

4IT49065 5698ISMSV 82LAUDIT LIBRARY FINISHES SUCCESSFULLY WHEN ERRORS AND WARNINGS ARE REPORTED

IT49064

3IT49064 5698ISMSV 82LAUDIT LIBVOLUME DOES NOT COMPARE THE BARCODE WITH THE INTERNAL LABEL

DT468772

 DT468772 5698ISMSV 82LUNEXPECTED DIFFERENT DEDUPLICATION AND COMPRESSION SAVINGS BETWEEN SOURCE AND TARGET IBM STORAGE PROTECT SERVERS POOLS

DT469333

 DT469333 5698ISMSV 82LAFTER UPGRADING IBM STORAGE PROTECT OPERATIONS CENTER TO VERSION 8.2.1, THE SERVER MAINTENANCE TASKS ARE NO LONGER VISIBLE IN THE SERVER MAINTENANCE WINDOW.

DT468897

 DT468897 5698ISMSV 82LUNABLE TO DELETE FILESPACE IF IT HAD DATA IN A RETENTION SET THAT IS DELETED BEFORE IT EXPIRES NATURALLY

DT469894

 DT469894 5698ISMSV 82LINCORRECT CATEGORY FOR TOTAL POOL RESERVATION NEGATIVE (XX, YY) MESSAGE IN TARGET SERVER DSMFFDC LOG DURING REPLICATION.

DT467700

 DT467700 5698ISMSV 82LANR8944E KEY/ASC/ASCQ 04/44/00 SENSE CODE DOES NOT PLACE DRIVE OFFLINE

DT470400

 DT470400 5698ISMSV 82LCLOUD CONTAINERS REMAIN IN AN UNAVAILABLE STATE DESPITE ZERO DAMAGED EXTENTS

DT469732

 DT469732 5698ISMSV 81LANR3716E A REQUEST TO THE AZURE CLOUD SERVICE PROVIDER FOR THE WRITE OBJECT OPERATION ON THE CLOUD-CONNECTION OR STORAGE POOL FAILED WITH THE FOLLOWING HTTP STATUS CODE: 409.

DT470905

 DT470905 5698ISMSV 82LIBM STORAGE PROTECT SERVER ON AIX REQUIRES THE MULTIHEAP PARAMETER TO BE SET TO 16 (MULTIHEAP:16). THIS REQUIREMENT IS DOCUMENTED IN BOTH THE BLUEPRINT AND THE AIX INSTALLATION GUIDE.

DT469187

 DT469187 5698ISMSV 82LDISABLE -SKIPUPGRADECHECK FLAG FOR SILENT INSTALLATION USING INSTALLATION MANAGER

IT48250

4IT48250 5698ISMSV 82LAFTER ADDING NEW DATA COLLECTION COMMANDS INTO COMMAND.INI FILE, THE COMMANDS ARE NOT RUN

DT468124

 DT468124 5698ISMSV 82LMISSING CLOSING QUOTATION MARK IN OPERATIONS CENTER NON-ROOT STARTUP DOCUMENTATION FOR LINUX

DT474942

 DT474942 5698ISMSV 82LIBM OPERATIONS CENTER (OC) – CLIENTS ELIGIBLE FOR DEPLOYMENT ON SPOKE SERVERS, SOMETIMES NOT SHOWING UP AS CANDIDATE

DT474187

 DT474187 5698ISMSV 82LANR1631I MESSAGE REPLICATION STATE INFORMATION FOR THE SPECIFIED NODES HAVE BEEN REMOVED USES THE WORD HAVE INCORRECTLY

IT49015

2IT49015 5698ISMSV 82LUPDATE AUDIT LIBRARY COMMAND IN IBM STORAGE PROTECT DOCUMENTATION

IT48994

3IT48994 5698ISMSV 82LINCOMPLETE DOCUMENTATION FOR TOTAL FILE SIZES IN QUERY RESULT SET OUTPUT

IT49081

2IT49081 5698ISMSV 82LREPAIR STGPOOL COMMAND HANGS WITH WAIT=YES AND PREVIEW=YES WHEN STGRULE REPLICATION IS SET ON THE POOL.

IT48933

4IT48933 5698ISMSV 82LUNDOCUMENTED FIELDS ENCRYPTED, COMPRESSED, AND COMPRESSED CAPACITY IN QUERY VOLUME

IT48252

3IT48252 5698ISMSV 82LTHE SERVERMON DATA COLLECTION MAY NOT COLLECT DSMFFDC LOGS

IT48166

2IT48166 5698ISMSV 82LTHE 'SERVERMON -STOP -FORCE' COMMAND MIGHT LEAVE A <DEFUNCT> PROCESS

DT473958

 DT473958 5698ISMSV 82LDISABLEREORGTABLE MANUAL PAGE SHOULD LIST ALL TABLES EXCLUDED FROM TABLE REORGANIZATION BY DEFAULT

IT45947

3IT45947 5698ISMSV 82LUSING AWS VIRTUAL-HOSTED-STYLE URL RESULTS IN ORPHANED RETENTION SET COPY VOLUMES

DT468065

 DT468065 5698ISMSV 82LIBM STORAGE PROTECT SERVER DATABASE BACKUP TO GOOGLE CLOUD FAILS AFTER UPGRADING TO VERSION 8.2.1

DT468229

 DT468229 5698ISMSV 82LANR2337W AND ANR2338E CAN BE SEEN WHEN THERE IS A MIX OF LBP AND NON-LBP DATA BLOCKS ON TAPE

DT469011

 DT469011 5698ISMSV 82LUNEXPECTED MESSAGE ANR3658E WHEN NO PROTECT STGPOOL PROCESS IS ACTIVE

DT468247

 DT468247 5698ISMSV 82LREPLICATION STGRULE MIGHT END WITH FAILURE DUE TO DATABASE DEADLOCK ON TARGET SERVER

DT470026

 DT470026 5698ISMSV 82LCLOUD CONTAINERS BECOME UNAVAILABLE AND ARE INCORRECTLY MARKED AS DAMAGED AFTER UPGRADING THE IBM STORAGE PROTECT SERVER TO VERSION 8.2.1

DT468813

 DT468813 5698ISMSV 82LIBM OPERATIONS CENTER (OC) CUSTOM REPORT - "SERVER" SELECTION MAY AUTOMATICALLY INCLUDE SERVER(S) WITH SIMILAR NAME

DT467792

 DT467792 5698ISMSV 82LIBM STORAGE PROTECT SERVERMON FAILS TO START ON AIX 7.3 TL4 POST UPGRADE

DT471296

 DT471296 5698ISMSV 82LAFTER UPGRADING OPERATIONS CENTER TO VERSION 8.2.1 THE STATUS LINKS DO NOT OPEN

 

Security vulnerabilities fixed in level 8.2.2.000

Security vulnerability
Abstract

CVE-2025-12383 

IBM Storage Protect Server uses the Eclipse Jersey Client library in certain components; Eclipse Jersey Client is vulnerable to a race condition that may lead to SSL/TLS security configurations issues.

CVE-2025-33012, CVE-2025-33134, CVE-2025-2534, CVE-2024-47118, CVE-2025-36006, CVE-2025-36008, CVE-2025-36131, CVE-2025-36136, CVE-2025-36186, CVE-2025-36185, CVE-2024-57699, 256137, 177835 

IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow denial of service, memory exhaustion, privilege escalation, improper authentication handling, or exposure of sensitive information under specific conditions.

CVE-2024-47072, CVE-2025-36442, CVE-2025-36428, CVE-2025-36427, CVE-2025-36424, CVE-2025-36407, CVE-2025-36387, CVE-2025-36366, CVE-2025-36384, CVE-2025-36365, CVE-2025-8916, CVE-2025-58056, CVE-2025-58057, CVE-2025-55163, CVE-2025-36353, CVE-2025-36098, CVE-2025-36123, CVE-2025-36070, CVE-2025-36009, CVE-2025-36001, CVE-2025-36184, CVE-2025-2668 

IBM Storage Protect Server uses the IBM Db2 database for certain components; Db2 contains multiple vulnerabilities that may allow service disruption, memory handling flaws, unauthorized privilege elevation, insufficient input sanitization, authentication-related weaknesses, and excessive resource consumption.

CVE-2025-36247, CVE-2025-36425, CVE-2025-13867, CVE-2025-14689 

IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow improper input handling, memory management weaknesses, and security control bypass conditions that could lead to service instability, denial of service, or unintended access under specific circumstances.

CVE-2025-5115 

IBM Storage Protect Server uses the Eclipse http2-common library in certain components; Eclipse http2-common library may allow a remote attacker to trigger denial-of-service conditions through specially crafted HTTP/2 requests.

CVE-2026-33870 

IBM Storage Protect Server uses the netty library in certain components; netty library may allow remote attacker to craft malicious HTTP requests to bypass intermediary parsing logic and inject unintended requests into backend connections, potentially impacting application integrity and security.

CVE-2026-33871 

IBM Storage Protect Server uses the netty library in certain components; netty library may allow improper handling of HTTP protocol processing under specific malformed request conditions.

CVE-2026-5795 

IBM Storage Protect Server uses the Eclipse Jetty web server library in certain components; Jetty may cause improper cleanup of ThreadLocal authentication data during request processing.

CVE-2025-36122, CVE-2025-14688, CVE-2025-67735, CVE-2025-68161, CVE-2025-12183, CVE-2026-1352, CVE-2026-1577, CVE-2026-3676 

IBM Storage Protect Server uses the IBM Db2 database; which may be affected by multiple vulnerabilities that may allow improper input handling, memory management flaws, authentication weaknesses, privilege escalation, and denial-of-service conditions.

CVE-2026-2332 

IBM Storage Protect Server uses the Eclipse Jetty web server library in certain components; Eclipse Jetty web server library may allow remote attacker to craft malicious HTTP requests to smuggle unintended backend requests, potentially leading to cache poisoning, access-control bypass, or request injection attacks.

CVE-2026-41417 

IBM Storage Protect Server uses the netty library in certain components; netty library may allow improper handling of network protocol processing and buffer management under specific malformed input conditions.

CVE-2026-42583 

IBM Storage Protect Server uses the netty library in certain components; netty library may allow improper validation and handling of specially crafted network input during protocol processing.

CVE-2026-42580, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42587 

IBM Storage Protect Server uses the netty library in certain components; netty library is affected by multiple vulnerabilities which may allow improper protocol handling, insufficient input validation, and resource management weaknesses when processing specially crafted network requests.

CVE-2026-42579 

IBM Storage Protect Server uses the netty library in certain components; netty library may allow insufficient validation and processing of maliciously crafted network requests during protocol handling.

CVE-2026-39824 

IBM Storage Protect Server uses the Golang sys library in OSSM and ObjectAgent component. Golang sys is vulnerable to data integrity issues.

CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598 

IBM Storage Protect Server uses the Golang crypto library in OSSM and ObjectAgent component. Golang crypto has multiple vulnerabilities that may cause denial of service, authentication and certificate validation bypasses or resource exhaustion.

CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-42502, CVE-2026-42506 

IBM Storage Protect Server uses the Golang net library in OSSM and ObjectAgent component. Golang net has multiple vulnerabilities that may cause input validation bypasses, and other unintended application behaviors through specially crafted network requests.

 

 

[{"Type":"MASTER","Line of Business":{"code":"LOB69","label":"Storage TPS"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSEGHY","label":"IBM Storage Protect"},"ARM Category":[{"code":"a8m3p000000hAZuAAM","label":"Server"}],"ARM Case Number":"","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"and future releases;8.2.0"}]

Document Information

Modified date:
31 July 2026

UID

ibm17253222