CVE-2023-47148
- EPSS 0.06%
- Published 02.02.2024 13:15:08
- Last modified 21.11.2024 08:29:52
IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-F...
CVE-2020-4497
- EPSS 0.05%
- Published 14.12.2022 22:15:10
- Last modified 21.11.2024 05:32:49
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the ...
CVE-2022-40608
- EPSS 0.7%
- Published 19.09.2022 18:15:10
- Last modified 21.11.2024 07:21:42
IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to f...
CVE-2022-40234
- EPSS 0.15%
- Published 19.09.2022 18:15:10
- Last modified 21.11.2024 07:21:07
Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus. If this generated .crt file...
CVE-2021-3669
- EPSS 0.01%
- Published 26.08.2022 16:15:09
- Last modified 21.11.2024 06:22:06
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
CVE-2022-22396
- EPSS 0.09%
- Published 06.06.2022 19:15:09
- Last modified 21.11.2024 06:46:45
Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Creden...
CVE-2022-22354
- EPSS 0.18%
- Published 14.03.2022 17:15:08
- Last modified 21.11.2024 06:46:41
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause t...
CVE-2021-39063
- EPSS 0.08%
- Published 13.12.2021 19:15:08
- Last modified 21.11.2024 06:18:31
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-...
CVE-2021-39057
- EPSS 0.12%
- Published 13.12.2021 19:15:08
- Last modified 21.11.2024 06:18:30
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitatin...
CVE-2020-4496
- EPSS 0.09%
- Published 13.12.2021 19:15:07
- Last modified 21.11.2024 05:32:48
The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.