Vulnerability Name: | CVE-2022-22485 (CCN-226325) | ||||||||||||
Assigned: | 2022-06-16 | ||||||||||||
Published: | 2022-06-16 | ||||||||||||
Updated: | 2022-06-28 | ||||||||||||
Summary: | In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to the IBM Spectrum Protect Server. IBM X-Force ID: 226325. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-287 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-22485 Source: XF Type: UNKNOWN ibm-spectrum-cve202222485-info-disc(226325) Source: XF Type: VDB Entry, Vendor Advisory ibm-spectrum-cve202222485-info-disc (226325) Source: CCN Type: IBM Security Bulletin 6595655 (Spectrum Protect Server) IBM Spectrum Protect Server may not count invalid sign-on attempts from Operations Center (CVE-2022-224485) Source: CONFIRM Type: Patch, Vendor Advisory https://www.ibm.com/support/pages/node/6595655 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |