Lucene search

K

Storage Defender Resiliency Service Security Vulnerabilities

cve
cve

CVE-2023-50957

IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783.

8CVSS

6.5AI Score

0.0005EPSS

2024-02-10 04:15 PM
29
cve
cve

CVE-2024-22312

IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.

5.5CVSS

5AI Score

0.0004EPSS

2024-02-10 04:15 PM
29
cve
cve

CVE-2024-22313

IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 278749.

7.8CVSS

7.5AI Score

0.0004EPSS

2024-02-10 04:15 PM
19
cve
cve

CVE-2024-25031

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute force account credentials. IBM X-Force ID: 281678.

6.5CVSS

6.3AI Score

0.0004EPSS

2024-06-28 07:15 PM
32
cve
cve

CVE-2024-27261

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. IBM X-Force ID: 283986.

6.4CVSS

6.2AI Score

0.0004EPSS

2024-04-12 01:15 PM
29
cve
cve

CVE-2024-38322

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869.

7.5CVSS

5.3AI Score

0.001EPSS

2024-06-28 07:15 PM
28