Ibm Spectrum Protect vulnerabilities
34 known vulnerabilities affecting ibm/spectrum_protect.
Total CVEs
34
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH9MEDIUM17
Vulnerabilities
Page 2 of 2
CVE-2023-27863P4MEDIUMCVSS 4.9v10.1.132023-05-12
CVE-2023-27863 [MEDIUM] CWE-200 CVE-2023-27863: IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated use
IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325.
nvd
CVE-2016-8939P4MEDIUMCVSS 5.5v7.1v8.12017-06-07
CVE-2016-8939 [MEDIUM] CWE-200 CVE-2016-8939: IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password informat
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.
nvd
CVE-2018-1787P4MEDIUMCVSS 5.5v7.1v8.12019-04-08
CVE-2018-1787 [MEDIUM] CWE-732 CVE-2018-1787: IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure
IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872.
nvd
CVE-2022-22484P4MEDIUMCVSS 5.5≥ 8.1.12.000, < 8.1.142022-05-17
CVE-2022-22484 [MEDIUM] CWE-312 CVE-2022-22484: IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sens
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By accessing browser history, an attacker could exploit this vulnerability to obtain other user accounts' passwords.
nvd
CVE-2020-5017P4MEDIUMCVSS 5.5≥ 10.1.0, < 10.1.72021-01-08
CVE-2020-5017 [MEDIUM] CVE-2020-5017: IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to informati
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended role and permissions. IBM X-Force ID: 193653.
nvd
CVE-2021-39048P4MEDIUMCVSS 5.5v7.1v8.12021-12-13
CVE-2021-39048 [MEDIUM] CWE-787 CVE-2021-39048: IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by im
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.
nvd
CVE-2021-20491P4MEDIUMCVSS 4.4≥ 7.1.0.000, < 7.1.13≥ 8.1.0.000, ≤ 8.1.10.100+1 more2021-04-16
CVE-2021-20491 [MEDIUM] CWE-787 CVE-2021-20491: IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improp
IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking during the parsing of commands. By issuing such a command with an improper parameter, an authorized administrator could overflow a buffer and cause the server to crash. IBM X-Force ID: 197792.
nvd
CVE-2018-1882P4MEDIUMCVSS 4.7v7.1v8.12019-04-08
CVE-2018-1882 [MEDIUM] CWE-312 CVE-2018-1882: In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be di
In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
nvd
CVE-2019-4236P4MEDIUMCVSS 4.4≥ 7.1.0.0, ≤ 7.1.8.5v7.l2019-07-22
CVE-2019-4236 [MEDIUM] CWE-19 CVE-2019-4236: A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is si
A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve the object with incorrect ACL entr
nvd
CVE-2018-1550P4MEDIUMCVSS 5.5v7.1v8.12018-09-26
CVE-2018-1550 [MEDIUM] CWE-269 CVE-2018-1550: IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive info
IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696.
nvd
CVE-2018-2025P4MEDIUMCVSS 4.4≥ 7.1.0.0, ≤ 7.1.8.5≥ 8.1.0.0, ≤ 8.1.8.02019-11-25
CVE-2018-2025 [MEDIUM] CWE-276 CVE-2018-2025: IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and
IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone. IBM X-Force ID: 155551.
nvd
CVE-2019-4093P4MEDIUMCVSS 4.4v8.1.72019-04-02
CVE-2019-4093 [MEDIUM] CWE-732 CVE-2019-4093: IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and dire
IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Spectrum Prootect Client Web User Interface on Windows that they should not have access to due to incorrect file permissions. IBM X-Force ID: 157981.
nvd
CVE-2017-1339P4MEDIUMCVSS 4.4v7.1v8.12017-10-05
CVE-2017-1339 [MEDIUM] CWE-327 CVE-2017-1339: IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for t
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum protect client or administrator password which can result in information disclosure or a denial of service. IBM X-Force ID: 126247.
nvd
CVE-2018-1788P4MEDIUMCVSS 4.4v7.1v8.12018-11-02
CVE-2018-1788 [MEDIUM] CWE-532 CVE-2018-1788: IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs t
IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.
nvd
← Previous2 / 2