VYPR

Spectrum Protect

by IBM

CVEs (66)

  • CVE-2020-4240MedMar 31, 2020
    risk 0.42cvss 6.5epss 0.02

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to overwrite or create arbitrary files on the system. IBM X-Force ID: 175417.

  • CVE-2019-4385MedJun 19, 2019
    risk 0.42cvss 6.5epss 0.00

    IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.

  • CVE-2023-33832MedJul 19, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM Spectrum Protect 8.1.0.0 through 8.1.17.0 could allow a local user to cause a denial of service due to due to improper time-of-check to time-of-use functionality. IBM X-Force ID: 256012.

  • CVE-2020-5020MedJan 8, 2021
    risk 0.40cvss 6.1epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly…

  • CVE-2018-1853MedApr 8, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions…

  • CVE-2022-40234MedSep 19, 2022
    risk 0.38cvss 5.9epss 0.01

    Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus. If this generated .crt file is shared, an attacker can…

  • CVE-2020-4496MedDec 13, 2021
    risk 0.38cvss 5.9epss 0.01

    The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.

  • CVE-2020-4783MedNov 23, 2020
    risk 0.38cvss 5.9epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the…

  • CVE-2020-4565MedJun 26, 2020
    risk 0.38cvss 5.9epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an attacker to obtain sensitive information due to insecure communications being used between the application and server. IBM X-Force ID: 183935.

  • CVE-2022-22484MedMay 17, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By accessing browser history, an attacker…

  • CVE-2021-20490MedJun 29, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791.

  • CVE-2020-5017MedJan 8, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended role and permissions. IBM X-Force ID: 193653.

  • CVE-2020-4631MedAug 4, 2020
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to cause interruption of the service operations. IBM X-Force ID: 185372.

  • CVE-2020-4954MedFeb 15, 2021
    risk 0.35cvss 5.4epss 0.01

    IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session using an attacker controlled IBM Spectrum Protect server, an…

  • CVE-2020-5022MedJan 8, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658.

  • CVE-2020-4209MedMay 4, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to create arbitrary files on the system. IBM X-Force ID: 175019.

  • CVE-2018-1786MedNov 12, 2018
    risk 0.35cvss 5.3epss 0.02

    IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.

  • CVE-2019-4703MedFeb 24, 2020
    risk 0.34cvss 5.3epss 0.00

    IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of the system to obtain highly sensitive information.

  • CVE-2018-1787MedApr 8, 2019
    risk 0.33cvss 5.1epss 0.00

    IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872.

  • CVE-2018-1882MedApr 8, 2019
    risk 0.31cvss 4.7epss 0.00

    In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.