CVE-2019-4385: Medium severity IBM Spectrum Protect Plus vulnerability
Published Jun 19, 2019
·Updated
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.
Affected Software
1 affected component
IBM Spectrum Protect Plus>=10.1.2.219<=10.1.2.303
Remediation
Patch Available
Event History
Jun 19, 2019
CVE Published
via MITRE·01:30 PM
Data Sourced
via MITRE·01:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4385?
CVE-2019-4385 has a medium severity rating due to the potential exposure of sensitive information.
2
How do I fix CVE-2019-4385?
To fix CVE-2019-4385, you should upgrade IBM Spectrum Protect Plus to a version beyond 10.1.2.303.
3
What systems are affected by CVE-2019-4385?
CVE-2019-4385 affects IBM Spectrum Protect Plus versions 10.1.2.219 to 10.1.2.303.
4
What are the potential impacts of CVE-2019-4385?
The potential impacts of CVE-2019-4385 include unauthorized access to sensitive data and vSnap resources.
5
Is CVE-2019-4385 a remote exploit?
CVE-2019-4385 is not classified as a remote exploit but poses a risk of information disclosure.