CVE-2021-39051
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the application server registration form in the portal UI to enumerate and attack services that are running on those hosts. IBM X-Force ID: 214441.
IBM Spectrum Copy Data Management versiones 2.2.0.0 hasta 2.2.14.3, es vulnerable a un ataque de tipo server-side request forgery, causada por la entrada inapropiada de la función de registro del servidor de aplicaciones. Un atacante remoto podría aprovechar esta vulnerabilidad usando los campos de dirección de host y puerto del formulario de registro del servidor de aplicaciones en la interfaz de usuario del portal para enumerar y atacar los servicios que son ejecutados en esos hosts. IBM X-Force ID: 214441
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-16 CVE Reserved
- 2022-03-14 CVE Published
- 2024-09-16 CVE Updated
- 2024-10-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/214441 | 2022-03-22 | |
https://www.ibm.com/support/pages/node/6562479 | 2022-03-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Spectrum Copy Data Management Search vendor "Ibm" for product "Spectrum Copy Data Management" | >= 2.2.0.0 < 2.2.15.0 Search vendor "Ibm" for product "Spectrum Copy Data Management" and version " >= 2.2.0.0 < 2.2.15.0" | - |
Affected
|