Offline Dictionary Attack Vulnerability in IBM Spectrum Protect Server
CVE-2022-22496

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
30 June 2022

Summary

IBM Spectrum Protect Server versions 8.1.0.000 through 8.1.14 are vulnerable when configured with SESSIONSECURITY=TRANSITIONAL. This setup can expose user accounts to offline dictionary attacks, where an attacker could potentially guess passwords by systematically testing a list of credentials without immediate feedback. It is crucial for impacted users to update configuration settings or upgrade to the latest version to mitigate this risk.

Affected Version(s)

Spectrum Protect Server 8.1.0.000

Spectrum Protect Server 8.1.14

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.