Access Control Vulnerability in IBM Spectrum Protect Plus Software
CVE-2022-22472
6MEDIUM
Summary
The IBM Spectrum Protect Plus software, specifically in versions 10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift, contains a flaw that allows a remote attacker to circumvent role-based access controls. This is accomplished through the improper disclosure of session information, which could be exploited by analyzing container logs. Such exploitation could enable unauthorized access to the system, leveraging the permissions of existing IBM Spectrum Protect Plus users against the vulnerable server instance.
Affected Version(s)
Spectrum Protect Plus 10.1.5
Spectrum Protect Plus 10.1.7
Spectrum Protect Plus 10.1.10.2
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved