First published: Fri Dec 10 2021(Updated: )
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 214616.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | >=10.1.0<10.1.9 | |
Linux Linux kernel | ||
<=10.1.0.0-10.1.8.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2021-39057.
The severity of CVE-2021-39057 is high with a score of 8.1.
IBM Spectrum Protect Plus is a data protection and recovery solution.
Server-side request forgery (SSRF) is a vulnerability that allows an attacker to make unauthorized requests on behalf of the server.
An authenticated attacker can exploit CVE-2021-39057 to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.