VYPR

Spectrum Protect Server

by IBM

CVEs (89)

  • CVE-2019-4652HigNov 12, 2019
    risk 0.46cvss 7.1epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170963.

  • CVE-2019-4140HigJul 2, 2019
    risk 0.46cvss 7.1epss 0.00

    IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IBM X-Force ID: 158336.

  • CVE-2020-4497MedDec 14, 2022
    risk 0.44cvss 6.8epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM…

  • CVE-2019-4383MedJul 1, 2019
    risk 0.44cvss 6.7epss 0.00

    When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle or MongoDB databases, a redirected restore operation may result in an escalation of user privileges. IBM X-Force ID: 162165.

  • CVE-2019-4357MedJul 1, 2019
    risk 0.44cvss 6.7epss 0.00

    When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirected restore operation specifying a target path may allow execution of arbitrary code on the system. IBM X-Force ID: 161667,

  • CVE-2022-22496MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.00

    While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942.

  • CVE-2021-20432MedApr 26, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 196344.

  • CVE-2020-5019MedJan 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which…

  • CVE-2020-4711MedSep 15, 2020
    risk 0.42cvss 6.5epss 0.03

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 187501.

  • CVE-2020-4477MedJun 15, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in further attacks against the system. IBM X-Force ID: 181779.

  • CVE-2020-4471MedJun 15, 2020
    risk 0.42cvss 6.5epss 0.03

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a specially crafted HTTP command to the remote server. IBM X-Force ID: 181726.

  • CVE-2020-4240MedMar 31, 2020
    risk 0.42cvss 6.5epss 0.02

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to overwrite or create arbitrary files on the system. IBM X-Force ID: 175417.

  • CVE-2019-4385MedJun 19, 2019
    risk 0.42cvss 6.5epss 0.00

    IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.

  • CVE-2021-20536MedApr 26, 2021
    risk 0.40cvss 6.2epss 0.00

    IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.

  • CVE-2020-5020MedJan 8, 2021
    risk 0.40cvss 6.1epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly…

  • CVE-2018-1853MedApr 8, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions…

  • CVE-2018-1550MedSep 26, 2018
    risk 0.40cvss 6.2epss 0.00

    IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696.

  • CVE-2022-40234MedSep 19, 2022
    risk 0.38cvss 5.9epss 0.01

    Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus. If this generated .crt file is shared, an attacker can…

  • CVE-2020-4496MedDec 13, 2021
    risk 0.38cvss 5.9epss 0.01

    The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.

  • CVE-2020-4783MedNov 23, 2020
    risk 0.38cvss 5.9epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the…