First published: Fri Jun 12 2020(Updated: )
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in further attacks against the system. IBM X-Force ID: 181779.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | >=10.1.0<=10.1.5 | |
IBM Spectrum Protect Plus | <=10.1.0-10.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4477.
The title of this vulnerability is 'IBM Spectrum Protect Plus discloses highly sensitive information in plain text in the virgo log file.'
The severity of CVE-2020-4477 is medium with a severity value of 6.5.
IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5 are affected by this vulnerability.
This vulnerability can be exploited by attackers who gain access to the virgo log file containing highly sensitive information in plain text.