Ibm Spectrum Protect vulnerabilities

34 known vulnerabilities affecting ibm/spectrum_protect.

Total CVEs
34
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH9MEDIUM17

Vulnerabilities

Page 2 of 2
CVE-2018-1787MEDIUMCVSS 5.5v7.1v8.12019-04-08
CVE-2018-1787 [MEDIUM] CWE-732 CVE-2018-1787: IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872.
cvelistv5nvd
CVE-2018-1853MEDIUMCVSS 6.1v7.1v8.12019-04-08
CVE-2018-1853 [MEDIUM] CWE-1021 CVE-2018-1853: IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijac IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 1
cvelistv5nvd
CVE-2018-1882MEDIUMCVSS 4.7v7.1v8.12019-04-08
CVE-2018-1882 [MEDIUM] CWE-312 CVE-2018-1882: In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be di In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
cvelistv5nvd
CVE-2019-4093MEDIUMCVSS 4.4v8.1.72019-04-02
CVE-2019-4093 [MEDIUM] CWE-732 CVE-2019-4093: IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and dire IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Spectrum Prootect Client Web User Interface on Windows that they should not have access to due to incorrect file permissions. IBM X-Force ID: 157981.
cvelistv5nvd
CVE-2018-1786HIGHCVSS 7.5≥ 8.1.0.0, ≤ 8.1.6.0v7.1+1 more2018-11-12
CVE-2018-1786 [HIGH] CWE-400 CVE-2018-1786: IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.
cvelistv5nvd
CVE-2018-1788MEDIUMCVSS 4.4v7.1v8.12018-11-02
CVE-2018-1788 [MEDIUM] CWE-532 CVE-2018-1788: IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs t IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.
cvelistv5nvd
CVE-2018-1785HIGHCVSS 7.5v7.1v8.12018-09-26
CVE-2018-1785 [HIGH] CWE-326 CVE-2018-1785: IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographi IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.
cvelistv5nvd
CVE-2018-1545HIGHCVSS 7.5v7.1v8.12018-09-26
CVE-2018-1545 [HIGH] CWE-326 CVE-2018-1545: IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographi IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649.
cvelistv5nvd
CVE-2018-1550MEDIUMCVSS 5.5v7.1v8.12018-09-26
CVE-2018-1550 [MEDIUM] CWE-269 CVE-2018-1550: IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive info IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696.
cvelistv5nvd
CVE-2018-1447HIGHCVSS 8.1v7.1v8.12018-04-04
CVE-2018-1447 [HIGH] CWE-916 CVE-2018-1447: The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4. The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Prod
cvelistv5nvd
CVE-2016-8937CRITICALCVSS 9.8v7.1v8.12017-10-05
CVE-2016-8937 [CRITICAL] CWE-287 CVE-2016-8937: The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to the TSM server. IBM X-Force ID: 118750.
cvelistv5nvd
CVE-2017-1339MEDIUMCVSS 4.4v7.1v8.12017-10-05
CVE-2017-1339 [MEDIUM] CWE-327 CVE-2017-1339: IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for t IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum protect client or administrator password which can result in information disclosure or a denial of service. IBM X-Force ID: 126247.
cvelistv5nvd
CVE-2017-1301MEDIUMCVSS 5.5v7.1v8.12017-10-05
CVE-2017-1301 [MEDIUM] CWE-59 CVE-2017-1301: IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectr IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various files on the system, which could allow the attacker to overwrite arbitrary
cvelistv5nvd
CVE-2016-8939MEDIUMCVSS 5.5v7.1v8.12017-06-07
CVE-2016-8939 [MEDIUM] CWE-200 CVE-2016-8939: IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password informat IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.
cvelistv5nvd