VYPR

Spectrum Protect Server

by IBM

CVEs (89)

  • CVE-2020-4565MedJun 26, 2020
    risk 0.38cvss 5.9epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an attacker to obtain sensitive information due to insecure communications being used between the application and server. IBM X-Force ID: 183935.

  • CVE-2022-22478MedJun 30, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.

  • CVE-2021-39048MedDec 13, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.

  • CVE-2021-20490MedJun 29, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791.

  • CVE-2020-5017MedJan 8, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended role and permissions. IBM X-Force ID: 193653.

  • CVE-2020-4631MedAug 4, 2020
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to cause interruption of the service operations. IBM X-Force ID: 185372.

  • CVE-2018-1768MedSep 26, 2018
    risk 0.36cvss 5.6epss 0.00

    IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in plain text within an instrumentation log file. IBM X-Force ID: 148622.

  • CVE-2017-1301MedOct 5, 2017
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various…

  • CVE-2016-8939MedJun 7, 2017
    risk 0.36cvss 5.5epss 0.00

    IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.

  • CVE-2020-5022MedJan 8, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658.

  • CVE-2020-4406MedJun 15, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the…

  • CVE-2020-4209MedMay 4, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to create arbitrary files on the system. IBM X-Force ID: 175019.

  • CVE-2019-4129MedJul 2, 2019
    risk 0.35cvss 5.3epss 0.02

    IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker could exploit this vulnerability to potentially obtain…

  • CVE-2018-1786MedNov 12, 2018
    risk 0.35cvss 5.3epss 0.02

    IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.

  • CVE-2015-4951MedJan 20, 2016
    risk 0.35cvss 5.3epss 0.01

    Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted Web client URL.

  • CVE-2019-4703MedFeb 24, 2020
    risk 0.34cvss 5.3epss 0.00

    IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of the system to obtain highly sensitive information.

  • CVE-2018-1787MedApr 8, 2019
    risk 0.33cvss 5.1epss 0.00

    IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872.

  • CVE-2018-1447MedApr 4, 2018
    risk 0.33cvss 5.1epss 0.01

    The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer…

  • CVE-2018-1882MedApr 8, 2019
    risk 0.31cvss 4.7epss 0.00

    In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.

  • CVE-2023-27863MedMay 12, 2023
    risk 0.29cvss 4.4epss 0.01

    IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325.

Page 4 of 5