PT-2021-22369 · Ibm · Ibm Spectrum Protect Plus
Published
2021-12-13
·
Updated
2021-12-15
·
CVE-2021-39063
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect Plus versions 10.1.0.0 through 10.1.8.x
Description
The issue is related to a misconfiguration in access control headers in the implementation of Cross-Origin Resource Sharing (CORS), which could allow an attacker to perform privileged actions and retrieve sensitive information.
Recommendations
For IBM Spectrum Protect Plus versions 10.1.0.0 through 10.1.8.x, consider reconfiguring the access control headers to properly restrict CORS, thereby preventing unauthorized access to sensitive information and privileged actions.
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Protect Plus