IBM Spectrum Virtualize information disclosure
CVE-2023-27870

5.9MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
11 May 2023

Summary

IBM Spectrum Virtualize 8.5 may allow unauthorized exposure of sensitive credential information during the download of updates from Fix Central. This vulnerability can arise under specific conditions, posing a risk to data integrity and protection. Organizations using this product should take immediate action to evaluate their setup and apply necessary mitigations as outlined in the IBM support advisory.

Affected Version(s)

Spectrum Virtualize 8.5

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.