CVE-2023-40368Sensitive Information Exposure in IBM Storage Protect Client

Severity
4.4MEDIUMNVD
EPSS
0.0%
top 95.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 20

Description

IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the administrative command line client. IBM X-Force ID: 263456.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5ibm/storage_protect_client8.1.0.08.1.19.0
NVDibm/storage_protect8.1.0.08.1.19.0
CVEListV5ibm/storage_protect_for_space_management8.1.0.08.1.19.0
CVEListV5ibm/storage_protect_for_virtual_environments8.1.0.08.1.19.0

Patches

🔴Vulnerability Details

2
CVEList
IBM Storage Protect information disclosure2023-09-20
GHSA
GHSA-g6mf-8rqc-v3x8: IBM Storage Protect 82023-09-20
CVE-2023-40368 — Sensitive Information Exposure in IBM | cvebase