First published: Tue Dec 13 2022(Updated: )
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | >=10.1.0<10.1.13 | |
IBM Spectrum Protect Plus | <=10.1.0-10.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4497.
The severity of CVE-2020-4497 is medium (6.8).
The affected software is IBM Spectrum Protect Plus version 10.1.0 through 10.1.12.
CVE-2020-4497 allows an attacker to obtain sensitive information through main-in-the-middle techniques due to unencrypted data being used in the communication flow.
To fix CVE-2020-4497, update IBM Spectrum Protect Plus to version 10.1.13 or later to ensure encrypted communication flow between Spectrum Protect Plus vSnap and its agents.