Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-38325
Disclosure Date: January 27, 2025 (last updated February 27, 2025)
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI
could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
0
Attacker Value
Unknown
CVE-2024-52361
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
stores user credentials in plain text which can be read by an authenticated user with access to the pod.
0
Attacker Value
Unknown
CVE-2024-47119
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client.
0
Attacker Value
Unknown
CVE-2023-50956
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.
0
Attacker Value
Unknown
CVE-2024-38322
Disclosure Date: June 28, 2024 (last updated February 26, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869.
0
Attacker Value
Unknown
CVE-2024-22313
Disclosure Date: February 10, 2024 (last updated February 26, 2025)
IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 278749.
0
Attacker Value
Unknown
CVE-2024-22312
Disclosure Date: February 10, 2024 (last updated February 26, 2025)
IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.
0
Attacker Value
Unknown
CVE-2023-50957
Disclosure Date: February 10, 2024 (last updated February 26, 2025)
IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783.
0