IBM Spectrum Virtualize information disclosure
CVE-2023-27870
5.9MEDIUM
Summary
IBM Spectrum Virtualize 8.5 may allow unauthorized exposure of sensitive credential information during the download of updates from Fix Central. This vulnerability can arise under specific conditions, posing a risk to data integrity and protection. Organizations using this product should take immediate action to evaluate their setup and apply necessary mitigations as outlined in the IBM support advisory.
Affected Version(s)
Spectrum Virtualize 8.5
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved