PT-2022-15409 · Ibm · Ibm Spectrum Protect Plus
Published
2022-06-06
·
Updated
2022-06-14
·
CVE-2022-22396
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect Plus versions 10.1.0.0 through 10.1.9.3
Description
The issue involves credentials being printed in clear text in the virgo log file under certain conditions. These credentials could include those for remote vSnap, offload targets, or VADP, depending on the operation being performed. However, credentials using API keys or certificates are not affected.
Recommendations
For versions 10.1.0.0 through 10.1.9.3, consider restricting access to the virgo log file to minimize the risk of credential exposure until a patch is available. As a temporary workaround, review and limit the use of operations that involve printing credentials to the log file.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Protect Plus