First published: Mon Jun 17 2019(Updated: )
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | >=10.1.2.219<=10.1.2.303 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4385 has a medium severity rating due to the potential exposure of sensitive information.
To fix CVE-2019-4385, you should upgrade IBM Spectrum Protect Plus to a version beyond 10.1.2.303.
CVE-2019-4385 affects IBM Spectrum Protect Plus versions 10.1.2.219 to 10.1.2.303.
The potential impacts of CVE-2019-4385 include unauthorized access to sensitive data and vSnap resources.
CVE-2019-4385 is not classified as a remote exploit but poses a risk of information disclosure.