CVE-2022-40234Resource Exposure in IBM Spectrum Protect Plus

CWE-668Resource Exposure3 documents3 sources
Severity
5.9MEDIUMNVD
EPSS
0.2%
top 63.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 19
Latest updateSep 20

Description

Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus. If this generated .crt file is shared, an attacker can obtain the private key information for the uploaded certificate. IBM X-Force ID: 235718.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/spectrum_protect_plus10.1.0, 10.1.11+1

🔴Vulnerability Details

2
GHSA
GHSA-rp88-5vg5-8wx2: Versions of IBM Spectrum Protect Plus prior to 102022-09-20
CVEList
CVE-2022-40234: Versions of IBM Spectrum Protect Plus prior to 102022-09-19
CVE-2022-40234 — Resource Exposure in IBM | cvebase