IBM Spectrum Protect Plus Server information disclosure
CVE-2023-27863

4.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
12 May 2023

Summary

IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325.

Affected Version(s)

Spectrum Protect Plus Server 10.1.13

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.