Brute Force Authentication Vulnerability in IBM Spectrum Protect Storage Agent
CVE-2022-22487

5.9MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
30 June 2022

Summary

The IBM Spectrum Protect storage agent is susceptible to a brute force authentication vulnerability that permits remote attackers to attempt unlimited login attempts without locking the administrative account. This flaw could allow unauthorized individuals to exploit the agent and subsequently gain access to the IBM Spectrum Protect Server it interfaces with, enabling potential unauthorized actions and access to sensitive data.

Affected Version(s)

Spectrum Protect Server 8.1.0.000

Spectrum Protect Server 8.1.14

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.