Lucene search

K
ibmIBM614F4AC4ABDF6371815CFFF0F56ADDBD96B8123584DAD096FE5C3185E422F1C3
HistoryJun 15, 2020 - 3:16 p.m.

Security Bulletin: IBM Spectrum Protect Plus is vulnerable to authentication bypass (CVE-2020-4216)

2020-06-1515:16:57
www.ibm.com
12

EPSS

0.012

Percentile

85.2%

Summary

IBM Spectrum Protect Plus is vulnerable to authentication bypass due to use of hard-coded credentials.

Vulnerability Details

CVEID:CVE-2020-4216
**DESCRIPTION:**IBM Spectrum Protect Plus contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/175066 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect Plus 10.1.0-10.1.5

Remediation/Fixes

Spectrum Protect Plus Release First Fixing VRM Level Platform Link to Fix
10.1 10.1.6 Linux <https://www.ibm.com/support/pages/node/5693313&gt;

Workarounds and Mitigations

None

EPSS

0.012

Percentile

85.2%

Related for 614F4AC4ABDF6371815CFFF0F56ADDBD96B8123584DAD096FE5C3185E422F1C3