Vulnerabilities > IBM > Spectrum Protect Plus > 10.1.10

DATE CVE VULNERABILITY TITLE RISK
2024-02-02 CVE-2023-47148 Unspecified vulnerability in IBM Spectrum Protect Plus
IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system.
network
low complexity
ibm
7.5
2022-12-14 CVE-2020-4497 Cleartext Transmission of Sensitive Information vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents.
network
high complexity
ibm CWE-319
5.9
2022-09-19 CVE-2022-40234 Exposure of Resource to Wrong Sphere vulnerability in IBM Spectrum Protect Plus
Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus.
network
high complexity
ibm CWE-668
5.9
2022-09-19 CVE-2022-40608 Path Traversal vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack.
network
low complexity
ibm CWE-22
7.5
2022-08-26 CVE-2021-3669 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A flaw was found in the Linux kernel.
local
low complexity
linux ibm debian fedoraproject redhat CWE-770
5.5