📦 Spectrum Protect Plus

by Ibm

🔍 What is Spectrum Protect Plus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-39063

CRITICAL CVSS 9.1 Dec 13, 2021

IBM Spectrum Protect Plus versions 10.1.0.0 through 10.1.8.x have a CORS misconfiguration that allows attackers to perform privileged actions and access sensitive information. This affects all deploym...

CVE-2020-4854

CRITICAL CVSS 9.8 Nov 23, 2020

IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6 contain hard-coded credentials used for authentication and encryption. This allows attackers to gain unauthorized access to the system and pote...

CVE-2022-22396

HIGH CVSS 7.5 Jun 6, 2022

IBM Spectrum Protect Plus versions 10.1.0.0 through 10.1.9.3 write credentials in clear text to virgo log files during certain operations. This exposes remote vSnap, offload targets, or VADP credentia...

CVE-2022-22354

HIGH CVSS 7.5 Mar 14, 2022

This vulnerability allows attackers to perform Slowloris HTTP denial-of-service attacks against IBM Spectrum Protect Plus and IBM Spectrum Copy Data Management. By keeping HTTP connections open withou...

CVE-2021-39057

HIGH CVSS 8.1 Dec 13, 2021

CVE-2021-39057 is a server-side request forgery (SSRF) vulnerability in IBM Spectrum Protect Plus that allows authenticated attackers to make unauthorized requests from the vulnerable server. This cou...

CVE-2021-29694

HIGH CVSS 7.5 Apr 26, 2021

IBM Spectrum Protect Plus versions 10.1.0 through 10.1.7 use weak cryptographic algorithms, allowing attackers to decrypt sensitive information. This affects organizations using these versions for dat...