Lucene search

K
ibmIBM1D9B29354854DE15E173F280D2DBB54A1E5402BB39099515C518A06F41FDFD7F
HistoryNov 26, 2020 - 12:39 a.m.

Security Bulletin: Improper Authentication of Websocket Endpoint in IBM Spectrum Protect Operations Center

2020-11-2600:39:20
www.ibm.com
9
ibm spectrum protect
operations center
websocket endpoint
remote attacker
sensitive information
cve-2020-4771
vulnerability
cveid
cvss
affected products
remediation
fixes

EPSS

0.001

Percentile

41.7%

Summary

Improper authentication of a websocket endpoint in IBM Spectrum Protect Operations Center could allow a remote attacker to obtain sensitive information.

Vulnerability Details

CVEID:CVE-2020-4771
**DESCRIPTION:**IBM Spectrum Protect Operations Center could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the websocket event stream, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/188993 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect Operations Center 8.1.0.000-8.1.10.xxx
7.1.0.000-7.1.11.xxx

Remediation/Fixes

IBM Spectrum Protect Operations Center Release First Fixing VRM Level Platform Link to Fix
8.1 8.1.11.000 AIX
Linux
Windows <http://www.ibm.com/support/pages/node/6368263&gt;
7.1 7.1.12.000 AIX
Linux
Windows

<https://www.ibm.com/support/pages/node/6368245&gt;

Workarounds and Mitigations

None

EPSS

0.001

Percentile

41.7%

Related for 1D9B29354854DE15E173F280D2DBB54A1E5402BB39099515C518A06F41FDFD7F