CVE-2020-4497: IBM Spectrum Protect Plus information disclosure
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106.
Other sources
IBM Spectrum Protect Plus discloses sensitive information due to unencryhpted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4497.
What is the severity of CVE-2020-4497?
The severity of CVE-2020-4497 is medium (6.8).
What is the affected software?
The affected software is IBM Spectrum Protect Plus version 10.1.0 through 10.1.12.
How does CVE-2020-4497 impact the affected software?
CVE-2020-4497 allows an attacker to obtain sensitive information through main-in-the-middle techniques due to unencrypted data being used in the communication flow.
How can I fix CVE-2020-4497?
To fix CVE-2020-4497, update IBM Spectrum Protect Plus to version 10.1.13 or later to ensure encrypted communication flow between Spectrum Protect Plus vSnap and its agents.