CVE-2023-47148 – IBM Storage Protect Plus Server information disclosure
https://notcve.org/view.php?id=CVE-2023-47148
IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 270599. IBM Storage Protect Plus Server 10.1.0 a 10.1.15.2 Admin Console podría permitir que un atacante remoto obtenga información confidencial debido a una validación inadecuada de endpoints no seguros que podrían usarse en futuros ataques contra el sistema. ID de IBM X-Force: 270599. • https://exchange.xforce.ibmcloud.com/vulnerabilities/270599 https://www.ibm.com/support/pages/node/7096482 • CWE-862: Missing Authorization •
CVE-2023-33832 – IBM Storage Protect denial of service
https://notcve.org/view.php?id=CVE-2023-33832
IBM Spectrum Protect 8.1.0.0 through 8.1.17.0 could allow a local user to cause a denial of service due to due to improper time-of-check to time-of-use functionality. IBM X-Force ID: 256012. • https://exchange.xforce.ibmcloud.com/vulnerabilities/256012 https://www.ibm.com/support/pages/node/7011761 • CWE-20: Improper Input Validation CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •
CVE-2023-28956 – IBM Spectrum Protect Backup-Archive Client privilege escalation
https://notcve.org/view.php?id=CVE-2023-28956
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. IBM X-Force ID: 251767. IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. • https://exchange.xforce.ibmcloud.com/vulnerabilities/251767 https://www.ibm.com/support/pages/node/7005519 • CWE-266: Incorrect Privilege Assignment •
CVE-2023-27863 – IBM Spectrum Protect Plus Server information disclosure
https://notcve.org/view.php?id=CVE-2023-27863
IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325. • https://exchange.xforce.ibmcloud.com/vulnerabilities/249325 https://www.ibm.com/support/pages/node/6965812 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2020-4497 – IBM Spectrum Protect Plus information disclosure
https://notcve.org/view.php?id=CVE-2020-4497
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106. IBM Spectrum Protect Plus 10.1.0 a 10.1.12 divulga información confidencial debido al uso de datos no cifrados en el flujo de comunicación entre Spectrum Protect Plus vSnap y sus agentes. Un atacante podría obtener información utilizando técnicas principales en el medio. • https://exchange.xforce.ibmcloud.com/vulnerabilities/182106 https://www.ibm.com/support/pages/node/6847627 • CWE-319: Cleartext Transmission of Sensitive Information •