PT-2022-15408 · Ibm · Ibm Spectrum Protect

Published

2022-03-21

·

Updated

2023-08-08

·

CVE-2022-22394

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect version 8.1.14.000
Description The issue is caused by improper enforcement of access controls, allowing a remote attacker to bypass security restrictions. By signing in, an attacker could exploit this to bypass security and gain unauthorized administrator or node access to the vulnerable server.
Recommendations For IBM Spectrum Protect version 8.1.14.000, consider restricting access to the server until a patch or fix is available to prevent unauthorized access. As a temporary workaround, review and strengthen access controls to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2022-22394

Affected Products

Ibm Spectrum Protect