PT-2021-12284 · Ibm · Ibm Spectrum Protect Plus

Published

2021-01-08

·

Updated

2021-01-13

·

CVE-2020-5018

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6
Description The issue allows sensitive information to be included in URLs, increasing the risk of this information being captured by an attacker.
Recommendations For IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6, consider restricting access to sensitive information and URLs to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5018

Affected Products

Ibm Spectrum Protect Plus