Insecure TLS Certificate Management in IBM Spectrum Protect Plus
CVE-2022-40234
5.9MEDIUM
What is CVE-2022-40234?
Versions of IBM Spectrum Protect Plus before 10.1.12 inadvertently include private key details within generated .crt files during TLS certificate uploads. If such a .crt file is distributed, it allows unauthorized access to the associated private key, creating a significant security risk. This vulnerability can facilitate attacks that compromise secure communications.
Affected Version(s)
Spectrum Protect Plus 10.1.0
Spectrum Protect Plus 10.1.11