Show filters
99 Total Results
Displaying 21-30 of 99
Sort by:
Attacker Value
Unknown

CVE-2022-22354

Disclosure Date: March 11, 2022 (last updated October 07, 2023)
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.
Attacker Value
Unknown

CVE-2021-39048

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.
Attacker Value
Unknown

CVE-2020-4496

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.
Attacker Value
Unknown

CVE-2021-39063

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force ID: 214956.
Attacker Value
Unknown

CVE-2021-38901

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Force ID: 209610.
Attacker Value
Unknown

CVE-2021-39057

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 214616.
Attacker Value
Unknown

CVE-2021-20490

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791.
Attacker Value
Unknown

CVE-2021-29694

Disclosure Date: April 24, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258.
Attacker Value
Unknown

CVE-2021-20532

Disclosure Date: April 24, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811.
Attacker Value
Unknown

CVE-2021-20536

Disclosure Date: April 24, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.