Weak Cryptographic Algorithms in IBM Spectrum Protect Plus Exploitable by Attackers
CVE-2021-29694

5.9MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 April 2021

Summary

IBM Spectrum Protect Plus versions 10.1.0 to 10.1.7 are affected by a vulnerability that utilizes weaker than anticipated cryptographic algorithms. This shortcoming allows potential attackers to decrypt sensitive information, posing significant risks to data integrity and confidentiality. The issue necessitates immediate attention to enhance security measures and protect against unauthorized data access.

Affected Version(s)

Spectrum Protect Plus 10.1.0

Spectrum Protect Plus 10.1.7

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.