Authentication Bypass in IBM Spectrum Copy Data Management
CVE-2022-22426

2.9LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
10 June 2022

Summary

IBM Spectrum Copy Data Management versions 2.2.0.0 through 2.2.15.0 are susceptible to an authentication bypass vulnerability due to improper session management. Local attackers could exploit this flaw to circumvent authentication mechanisms, gaining unauthorized access to the Spectrum Copy Data Management catalog, which contains sensitive metadata. This vulnerability raises significant security concerns, as it may allow malicious actors to manipulate or exfiltrate critical data without proper authentication. Prompt assessment and remediation of this issue are crucial for safeguarding data integrity.

Affected Version(s)

Spectrum Copy Data Management 2.2.0.0

Spectrum Copy Data Management 2.2.15.0

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.