Show filters
99 Total Results
Displaying 1-10 of 99
Sort by:
Attacker Value
Unknown
CVE-2023-47148
Disclosure Date: February 02, 2024 (last updated February 09, 2024)
IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 270599.
0
Attacker Value
Unknown
CVE-2023-33832
Disclosure Date: July 19, 2023 (last updated October 08, 2023)
IBM Spectrum Protect 8.1.0.0 through 8.1.17.0 could allow a local user to cause a denial of service due to due to improper time-of-check to time-of-use functionality. IBM X-Force ID: 256012.
0
Attacker Value
Unknown
CVE-2023-28956
Disclosure Date: June 22, 2023 (last updated September 27, 2024)
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls.
0
Attacker Value
Unknown
CVE-2023-27863
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325.
0
Attacker Value
Unknown
CVE-2020-4497
Disclosure Date: December 14, 2022 (last updated November 08, 2023)
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106.
0
Attacker Value
Unknown
CVE-2022-40234
Disclosure Date: September 17, 2022 (last updated October 08, 2023)
Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus. If this generated .crt file is shared, an attacker can obtain the private key information for the uploaded certificate. IBM X-Force ID: 235718.
0
Attacker Value
Unknown
CVE-2022-40608
Disclosure Date: September 17, 2022 (last updated October 08, 2023)
IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID: 235873.
0
Attacker Value
Unknown
CVE-2021-3669
Disclosure Date: August 26, 2022 (last updated October 08, 2023)
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
0
Attacker Value
Unknown
CVE-2022-22494
Disclosure Date: June 29, 2022 (last updated October 07, 2023)
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.
0
Attacker Value
Unknown
CVE-2022-22478
Disclosure Date: June 29, 2022 (last updated October 07, 2023)
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.
0