CVE-2020-4591

Severity
3.3LOW
EPSS
0.0%
top 93.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 28
Latest updateMay 24

Description

IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted container pool. IBM X-Force ID: 184746.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDibm/spectrum_protect_server8.1.0.0008.1.10.000
CVEListV5ibm/spectrum_protect_server8.1.0.000, 8.1.10.000+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6xvh-rff7-qx7f: IBM Spectrum Protect Server 82022-05-24
CVEList
CVE-2020-4591: IBM Spectrum Protect Server 82020-08-28
CVE-2020-4591 (LOW CVSS 3.3) | IBM Spectrum Protect Server 8.1.0.0 | cvebase.io