Ibm Storage Defender vulnerabilities
4 known vulnerabilities affecting ibm/storage_defender.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-38325HIGHCVSS 7.5≥ 2.0.0, < 2.0.82025-01-27
CVE-2024-38325 [MEDIUM] CWE-311 CVE-2024-38325: IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI
could allow a remote atta
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI
could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
nvd
CVE-2024-38324MEDIUMCVSS 6.5≥ 2.0.0, < 2.0.82024-09-25
CVE-2024-38324 [MEDIUM] CWE-297 CVE-2024-38324: IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server na
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.
nvd
CVE-2024-25031MEDIUMCVSS 6.5≥ 2.0.0, ≤ 2.0.42024-06-28
CVE-2024-25031 [MEDIUM] CWE-307 CVE-2024-25031: IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout set
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute force account credentials. IBM X-Force ID: 281678.
nvd
CVE-2024-27261MEDIUMCVSS 6.8≥ 2.0.0, ≤ 2.0.22024-04-12
CVE-2024-27261 [MEDIUM] CWE-749 CVE-2024-27261: IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to insta
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. IBM X-Force ID: 283986.
cvelistv5nvd