Improper Authentication in IBM Spectrum Protect Operations Center
CVE-2020-4771

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
23 November 2020

Summary

IBM Spectrum Protect Operations Center versions 8.1.0.000 to 8.1.10 and 7.1.0.000 to 7.1.11 are vulnerable due to improper authentication of a websocket endpoint. This flaw allows remote attackers to subscribe to the websocket event stream using readily available tools, potentially exposing sensitive information. This vulnerability could have serious implications for organizations relying on these versions, as it enables unauthorized access to critical data.

Affected Version(s)

Spectrum Protect Operations Center 8.1

Spectrum Protect Operations Center 8.1.10

Spectrum Protect Operations Center 7.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.