Lucene search

K
cvelistIbmCVELIST:CVE-2022-22485
HistoryJun 17, 2022 - 3:20 p.m.

CVE-2022-22485

2022-06-1715:20:14
ibm
www.cve.org
1
ibm spectrum protect
unauthorized access
ibm x-force id

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

AI Score

9.1

Confidence

High

EPSS

0.002

Percentile

52.7%

In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator’s invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to the IBM Spectrum Protect Server. IBM X-Force ID: 226325.

CNA Affected

[
  {
    "product": "Spectrum Protect Server",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "8.1.0.000"
      },
      {
        "status": "affected",
        "version": "8.1.14.000"
      }
    ]
  }
]

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

AI Score

9.1

Confidence

High

EPSS

0.002

Percentile

52.7%

Related for CVELIST:CVE-2022-22485