CVE-2024-22314
- EPSS 0.01%
- Veröffentlicht 16.04.2025 16:17:54
- Zuletzt bearbeitet 19.08.2025 16:39:38
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2024-47119
- EPSS 0.04%
- Veröffentlicht 18.12.2024 16:15:13
- Zuletzt bearbeitet 08.08.2025 13:10:07
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client.
CVE-2024-52361
- EPSS 0.03%
- Veröffentlicht 18.12.2024 16:15:13
- Zuletzt bearbeitet 08.08.2025 12:53:47
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 stores user credentials in plain text which can be read by an authenticated user with access to the pod.
CVE-2023-50956
- EPSS 0.05%
- Veröffentlicht 18.12.2024 16:15:10
- Zuletzt bearbeitet 09.08.2025 01:48:39
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.
CVE-2024-38322
- EPSS 0.09%
- Veröffentlicht 28.06.2024 19:15:06
- Zuletzt bearbeitet 21.11.2024 09:25:22
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869.
CVE-2024-27261
- EPSS 0.03%
- Veröffentlicht 12.04.2024 13:15:15
- Zuletzt bearbeitet 10.03.2025 16:18:05
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. IBM X-Force ID: 283986.
CVE-2024-22312
- EPSS 0.02%
- Veröffentlicht 10.02.2024 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:56:02
IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.
CVE-2024-22313
- EPSS 0.02%
- Veröffentlicht 10.02.2024 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:56:02
IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. ...
CVE-2023-50957
- EPSS 0.04%
- Veröffentlicht 10.02.2024 16:15:07
- Zuletzt bearbeitet 21.11.2024 08:37:36
IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783.