CVE-2022-22368: Weak Encryption
Published Apr 26, 2022
·Updated
IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012.
Other sources
IBM Spectrum Scale uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Affected Software
5 affected components
IBM Spectrum Scale<=5.1.0 - 5.1.3.0
IBM Spectrum Scale>=5.1.0<=5.1.3.0
IBM AIX
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Apr 26, 2022
CVE Published
via IBM·12:00 AM
May 3, 2022
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-22368.
2
What is the severity of CVE-2022-22368?
The severity of CVE-2022-22368 is high, with a severity value of 7.5.
3
How does the vulnerability impact IBM Spectrum Scale?
The vulnerability in IBM Spectrum Scale could allow an attacker to decrypt highly sensitive information.
4
Which versions of IBM Spectrum Scale are affected by this vulnerability?
IBM Spectrum Scale versions 5.1.0 through 5.1.3.0 are affected by this vulnerability.
5
How can I fix the vulnerability in IBM Spectrum Scale?
To fix the vulnerability in IBM Spectrum Scale, update to a version beyond 5.1.3.0 that uses stronger cryptographic algorithms.