Weak Cryptographic Algorithms in IBM Spectrum Protect Plus Exploitable by Attackers
CVE-2021-29694
5.9MEDIUM
Summary
IBM Spectrum Protect Plus versions 10.1.0 to 10.1.7 are affected by a vulnerability that utilizes weaker than anticipated cryptographic algorithms. This shortcoming allows potential attackers to decrypt sensitive information, posing significant risks to data integrity and confidentiality. The issue necessitates immediate attention to enhance security measures and protect against unauthorized data access.
Affected Version(s)
Spectrum Protect Plus 10.1.0
Spectrum Protect Plus 10.1.7
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved