PT-2022-15466 · Ibm · Ibm Spectrum Protect Server+1
Published
2022-06-30
·
Updated
2023-08-08
·
CVE-2022-22487
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect Server versions 8.1.0.000 through 8.1.14
Description
A remote attacker could perform a brute force attack by making unlimited attempts to login to the storage agent without locking the administrative ID. This could allow the attacker to gain unauthorized administrative access to both the IBM Spectrum Protect storage agent and the IBM Spectrum Protect Server with which it communicates.
Recommendations
For versions 8.1.0.000 through 8.1.14, consider implementing a lockout policy for the administrative ID after a specified number of failed login attempts to mitigate the risk of brute force attacks. As a temporary workaround, restrict access to the storage agent to minimize the risk of exploitation.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Protect Server
Ibm Spectrum Protect Storage Agents