Improper Authentication in IBM Spectrum Protect Operations Center
CVE-2020-4771
5.3MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 23 November 2020
Summary
IBM Spectrum Protect Operations Center versions 8.1.0.000 to 8.1.10 and 7.1.0.000 to 7.1.11 are vulnerable due to improper authentication of a websocket endpoint. This flaw allows remote attackers to subscribe to the websocket event stream using readily available tools, potentially exposing sensitive information. This vulnerability could have serious implications for organizations relying on these versions, as it enables unauthorized access to critical data.
Affected Version(s)
Spectrum Protect Operations Center 8.1
Spectrum Protect Operations Center 8.1.10
Spectrum Protect Operations Center 7.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved