Show filters
99 Total Results
Displaying 21-30 of 99
Sort by:
Attacker Value
Unknown
CVE-2022-22354
Disclosure Date: March 11, 2022 (last updated October 07, 2023)
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.
0
Attacker Value
Unknown
CVE-2021-39048
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.
0
Attacker Value
Unknown
CVE-2020-4496
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.
0
Attacker Value
Unknown
CVE-2021-39063
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force ID: 214956.
0
Attacker Value
Unknown
CVE-2021-38901
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Force ID: 209610.
0
Attacker Value
Unknown
CVE-2021-39057
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 214616.
0
Attacker Value
Unknown
CVE-2021-20490
Disclosure Date: June 28, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791.
0
Attacker Value
Unknown
CVE-2021-29694
Disclosure Date: April 24, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258.
0
Attacker Value
Unknown
CVE-2021-20532
Disclosure Date: April 24, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811.
0
Attacker Value
Unknown
CVE-2021-20536
Disclosure Date: April 24, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.
0