Sensitive Information Disclosure in IBM Spectrum Protect Plus File Systems Agent
CVE-2021-20536

6.2MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 April 2021

Summary

IBM Spectrum Protect Plus File Systems Agent versions 10.1.6 and 10.1.7 improperly store potentially sensitive information in log files. This sensitive data can be accessed by local users, which poses a risk of unauthorized information retrieval. Organizations utilizing these affected versions should consider reviewing their log file management practices to mitigate the risk of exposure.

Affected Version(s)

Spectrum Protect Plus 10.1.6

Spectrum Protect Plus 10.1.7

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.