Offline Dictionary Attack Vulnerability in IBM Spectrum Protect Server
CVE-2022-22496
5.3MEDIUM
Summary
IBM Spectrum Protect Server versions 8.1.0.000 through 8.1.14 are vulnerable when configured with SESSIONSECURITY=TRANSITIONAL. This setup can expose user accounts to offline dictionary attacks, where an attacker could potentially guess passwords by systematically testing a list of credentials without immediate feedback. It is crucial for impacted users to update configuration settings or upgrade to the latest version to mitigate this risk.
Affected Version(s)
Spectrum Protect Server 8.1.0.000
Spectrum Protect Server 8.1.14
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved