CVE-2021-39057: SSRF
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 214616.
Other sources
IBM Spectrum Protect Plus is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2021-39057.
What is the severity of CVE-2021-39057?
The severity of CVE-2021-39057 is high with a score of 8.1.
What is IBM Spectrum Protect Plus?
IBM Spectrum Protect Plus is a data protection and recovery solution.
What is server-side request forgery (SSRF)?
Server-side request forgery (SSRF) is a vulnerability that allows an attacker to make unauthorized requests on behalf of the server.
How can an attacker exploit CVE-2021-39057?
An authenticated attacker can exploit CVE-2021-39057 to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.