CVE-2022-39167Sensitive Information Exposure in IBM Spectrum Virtualize

Severity
5.9MEDIUMNVD
EPSS
0.3%
top 49.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 19

Description

IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information to an attacker using man-in-the-middle techniques. IBM X-Force ID: 235408.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/spectrum_virtualize8.5, 8.4, 8.3, 8.2, 7.8
NVDibm/spectrum_virtualize5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-86rp-q4q2-g9m2: IBM Spectrum Virtualize 82023-01-19
CVEList
IBM Spectrum Virtualize information disclosure2023-01-19
CVE-2022-39167 — Sensitive Information Exposure in IBM | cvebase