CVE-2022-22354: High severity ibm storage protect plus vulnerability
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.
Other sources
IBM Spectrum Protect Plus and IBM Spectrum Copy Data Management do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22354?
CVE-2022-22354 is a vulnerability in IBM Spectrum Protect Plus and IBM Spectrum Copy Data Management that allows for a Slowloris HTTP denial of service attack.
Which products are affected by CVE-2022-22354?
IBM Spectrum Protect Plus versions 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management versions 2.2.0.0 through 2.2.14.3 are affected by CVE-2022-22354.
What is the severity of CVE-2022-22354?
CVE-2022-22354 has a severity rating of 7.5 (High).
How can CVE-2022-22354 be exploited?
CVE-2022-22354 can be exploited by sending a specially crafted connection to the affected IBM products, causing a Slowloris HTTP denial of service attack.
Are there any references for CVE-2022-22354?
Yes, you can find more information about CVE-2022-22354 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/220485), [Reference 2](https://www.ibm.com/support/pages/node/6562479), [Reference 3](https://www.ibm.com/support/pages/node/6562989).