First published: Fri Mar 11 2022(Updated: )
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Copy Data Management | >=2.2.0.0<2.2.15 | |
IBM Spectrum Protect Plus | >=10.1.0<10.1.9.3 | |
Linux Linux kernel | ||
<=10.1.0.0-10.1.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22354 is a vulnerability in IBM Spectrum Protect Plus and IBM Spectrum Copy Data Management that allows for a Slowloris HTTP denial of service attack.
IBM Spectrum Protect Plus versions 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management versions 2.2.0.0 through 2.2.14.3 are affected by CVE-2022-22354.
CVE-2022-22354 has a severity rating of 7.5 (High).
CVE-2022-22354 can be exploited by sending a specially crafted connection to the affected IBM products, causing a Slowloris HTTP denial of service attack.
Yes, you can find more information about CVE-2022-22354 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/220485), [Reference 2](https://www.ibm.com/support/pages/node/6562479), [Reference 3](https://www.ibm.com/support/pages/node/6562989).