cbcvebase.

Ibm Spectrum Protect Plus vulnerabilities

51 known vulnerabilities affecting ibm/spectrum_protect_plus.

Total CVEs
51
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH17MEDIUM24

Vulnerabilities

Page 3 of 3
CVE-2019-4385P4MEDIUMCVSS 6.5≥ 10.1.2.219, ≤ 10.1.2.303v10.1.22019-06-19
CVE-2019-4385 [MEDIUM] CWE-522 CVE-2019-4385: IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plu IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.
nvd
CVE-2020-5020P4MEDIUMCVSS 6.1≥ 10.1.0, < 10.1.7v10.1.0+1 more2021-01-08
CVE-2020-5020 [MEDIUM] CWE-1021 CVE-2020-5020: IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 193656.
nvd
CVE-2020-4783P4MEDIUMCVSS 5.9≥ 10.1.0, ≤ 10.1.6v10.1.0+1 more2020-11-23
CVE-2020-4783 [MEDIUM] CWE-862 CVE-2020-4783: IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive in IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 189214.
nvd
CVE-2020-5022P4MEDIUMCVSS 5.3≥ 10.1.0, < 10.1.7v10.1.0+1 more2021-01-08
CVE-2020-5022 [MEDIUM] CWE-306 CVE-2020-5022: IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658.
nvd
CVE-2021-20536P4MEDIUMCVSS 6.2v10.1.6v10.1.72021-04-26
CVE-2021-20536 [MEDIUM] CWE-532 CVE-2021-20536: IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive informat IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.
nvd
CVE-2019-4703P4MEDIUMCVSS 5.3≥ 10.1.0, ≤ 10.1.5v10.1.0+1 more2020-02-24
CVE-2019-4703 [MEDIUM] CVE-2019-4703: IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, co IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of the system to obtain highly sensitive information.
nvd
CVE-2020-5017P4MEDIUMCVSS 5.5v10.1.0v10.1.62021-01-08
CVE-2020-5017 [MEDIUM] CVE-2020-5017: IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to informati IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended role and permissions. IBM X-Force ID: 193653.
nvd
CVE-2021-3669P4MEDIUMCVSS 5.5≥ 10.1.0, ≤ 10.1.10.22022-08-26
CVE-2021-3669 [MEDIUM] CWE-400 CVE-2021-3669: A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
nvd
CVE-2020-4631P4MEDIUMCVSS 5.5≥ 10.1.0, ≤ 10.1.6v10.1.0+1 more2020-08-04
CVE-2020-4631 [MEDIUM] CWE-732 CVE-2020-4631: IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windo IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to cause interruption of the service operations. IBM X-Force ID: 185372.
nvd
CVE-2021-20490P4MEDIUMCVSS 5.5≥ 10.1.0, ≤ 10.1.8v10.1.0+1 more2021-06-29
CVE-2021-20490 [MEDIUM] CWE-276 CVE-2021-20490: IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of servic IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791.
nvd
CVE-2020-5021P4MEDIUMCVSS 4.4≥ 10.1.0, < 10.1.7v10.1.0+1 more2021-01-08
CVE-2020-5021 [MEDIUM] CWE-384 CVE-2020-5021: IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset w IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657.
nvd