PT-2022-4249 · Ibm · Ibm Spectrum Virtualize

Published

2022-05-11

·

Updated

2022-05-19

·

CVE-2021-38969

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Spectrum Virtualize versions 8.2 through 8.4
Description The issue is related to a hardcoded credential mechanism in the authentication process of the software. This could allow a remote attacker to gain unauthorized access and elevate their privileges.
Recommendations For IBM Spectrum Virtualize versions 8.2 through 8.4, consider restricting access to the system until a patch is available to prevent potential exploitation of the hardcoded credentials issue. As a temporary workaround, avoid using the support generated credentials in the affected versions until the issue is resolved.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05099
CVE-2021-38969

Affected Products

Ibm Spectrum Virtualize