Vulnerability Name: | CVE-2022-22396 (CCN-222231) | ||||||||||||
Assigned: | 2022-06-02 | ||||||||||||
Published: | 2022-06-02 | ||||||||||||
Updated: | 2022-06-14 | ||||||||||||
Summary: | Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key or certificate are not printed. IBM X-Force ID: 222231. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-522 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-22396 Source: XF Type: UNKNOWN ibm-spectrum-cve202222396-info-disc(222231) Source: XF Type: VDB Entry, Vendor Advisory ibm-spectrum-cve202222396-info-disc (222231) Source: CCN Type: IBM Security Bulletin 6591505 (Spectrum Protect Plus) IBM Spectrum Protect Plus may disclose sensitive information in virgo log file (CVE-2022-22396) Source: CONFIRM Type: Vendor Advisory https://www.ibm.com/support/pages/node/6591505 | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |