First published: Fri Mar 18 2022(Updated: )
The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrator or node access to the vulnerable server.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect | =8.1.14.100 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
<=8.1.14.000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22394 is critical with a CVSS score of 8.8.
CVE-2022-22394 affects IBM Spectrum Protect 8.1.14.000 server by allowing a remote attacker to bypass security restrictions.
An attacker can exploit CVE-2022-22394 by signing in and bypassing security to gain unauthorized administrator or node access.
No, IBM AIX is not vulnerable to CVE-2022-22394.
You can find more information about CVE-2022-22394 at the following links: - [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/222147) - [IBM Support](https://www.ibm.com/support/pages/node/6564745)