PT-2022-15408 · Ibm · Ibm Spectrum Protect
Published
2022-03-21
·
Updated
2023-08-08
·
CVE-2022-22394
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect version 8.1.14.000
Description
The issue is caused by improper enforcement of access controls, allowing a remote attacker to bypass security restrictions. By signing in, an attacker could exploit this to bypass security and gain unauthorized administrator or node access to the vulnerable server.
Recommendations
For IBM Spectrum Protect version 8.1.14.000, consider restricting access to the server until a patch or fix is available to prevent unauthorized access. As a temporary workaround, review and strengthen access controls to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Spectrum Protect