cbcvebase.
CVE-2023-47148
published 2024-02-02

CVE-2023-47148: IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.61%
45.1th percentile
IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 270599.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmspectrum_protect_plus>= 10.1.0 < 10.1.15.310.1.15.3
ibmstorage_protect_plus_server10.1.0 – 10.1.15.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.