CVE-2022-43870Log File Information Exposure in IBM Spectrum Virtualize

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 44.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 22

Description

IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/spectrum_virtualize8.3, 8.4, 8.5
NVDibm/spectrum_virtualize8.3.0.0, 8.4.0.0, 8.5.0.0+2

🔴Vulnerability Details

2
CVEList
IBM Spectrum Virtualize information disclosure2023-02-22
GHSA
GHSA-h8r2-7g59-cc4p: IBM Spectrum Virtualize 82023-02-22
CVE-2022-43870 — Log File Information Exposure in IBM | cvebase