PT-2022-15409 · Ibm · Ibm Spectrum Protect Plus

Published

2022-06-06

·

Updated

2022-06-14

·

CVE-2022-22396

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect Plus versions 10.1.0.0 through 10.1.9.3
Description The issue involves credentials being printed in clear text in the virgo log file under certain conditions. These credentials could include those for remote vSnap, offload targets, or VADP, depending on the operation being performed. However, credentials using API keys or certificates are not affected.
Recommendations For versions 10.1.0.0 through 10.1.9.3, consider restricting access to the virgo log file to minimize the risk of credential exposure until a patch is available. As a temporary workaround, review and limit the use of operations that involve printing credentials to the log file.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22396

Affected Products

Ibm Spectrum Protect Plus