IBM Spectrum Protect Plus is a data protection platform from IBM USA. The platform provides enterprises with a single point of control and management, and supports backup and recovery for virtual, physical and cloud environments of all sizes.A security vulnerability exists in IBM Spectrum Protect Plus, which stems from the fact that IBM Spectrum Protect Plus uses cross-source resource sharing (CORS), but is misconfigured in the access control header. An attacker could exploit the vulnerability to perform privileged operations and retrieve sensitive information.