Skip to main content

Vendor/product archive

ibm / spectrum_protect_plus CVEs

Beta · best-effort

44 CVEs tagged to ibm / spectrum_protect_plus5 Critical, 14 High, 25 Medium, 0 Low, 0 Unrated.

CVE-2020-4497

Published Dec 14, 2022

IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40608

Published Sep 19, 2022

IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory trav…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40234

Published Sep 19, 2022

Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TL…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20432

Published Apr 26, 2021

IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive info…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5023

Published Feb 10, 2021

IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to excess resource consumption. IBM…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4711

Published Sep 15, 2020

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request contain…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4703

Published Sep 15, 2020

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 44 CVEsPage 1 of 2