Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2023-25681
Disclosure Date: March 05, 2024 (last updated March 06, 2024)
LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and password. This does not affect local users with MFA configured or remote users authenticating via single sign-on. IBM X-Force ID: 247033.
0
Attacker Value
Unknown
CVE-2023-27870
Disclosure Date: May 11, 2023 (last updated January 25, 2025)
IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a download from Fix Central is in progress. IBM X-Force ID: 249518.
0
Attacker Value
Unknown
CVE-2022-43873
Disclosure Date: February 22, 2023 (last updated November 08, 2023)
An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute code and escalate their privilege on the system. IBM X-Force ID: 239847.
0
Attacker Value
Unknown
CVE-2022-43870
Disclosure Date: February 22, 2023 (last updated November 08, 2023)
IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.
0
Attacker Value
Unknown
CVE-2022-39167
Disclosure Date: January 19, 2023 (last updated November 08, 2023)
IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information to an attacker using man-in-the-middle techniques. IBM X-Force ID: 235408.
0
Attacker Value
Unknown
CVE-2021-38969
Disclosure Date: May 10, 2022 (last updated October 07, 2023)
IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609.
0
Attacker Value
Unknown
CVE-2021-29873
Disclosure Date: October 20, 2021 (last updated November 28, 2024)
IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.
0
Attacker Value
Unknown
CVE-2020-4686
Disclosure Date: August 17, 2020 (last updated November 28, 2024)
IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to. IBM X-Force ID: 186678.
0
Attacker Value
Unknown
CVE-2018-1775
Disclosure Date: February 27, 2019 (last updated November 27, 2024)
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.
0
Attacker Value
Unknown
CVE-2018-1438
Disclosure Date: May 17, 2018 (last updated November 26, 2024)
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DLSnap could allow an unauthenticated attacker to read arbitrary files on the system. IBM X-Force ID: 139566.
0