First published: Fri Feb 21 2020(Updated: )
IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of the system to obtain highly sensitive information.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | >=10.1.0<=10.1.5 | |
<=10.1.0-10.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-4703.
The severity of CVE-2019-4703 is medium with a CVSS score of 5.3.
IBM Spectrum Protect Plus versions 10.1.0 to 10.1.5 are affected by CVE-2019-4703.
An attacker with intimate knowledge of the system can exploit this vulnerability to obtain highly sensitive information when protecting Microsoft SQL or Microsoft Exchange with IBM Spectrum Protect Plus.
More information about CVE-2019-4703 can be found at the following references: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/172013), [Link 2](https://www.ibm.com/support/pages/node/3177915).