First published: Thu Jun 09 2022(Updated: )
IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication restrictions, caused by the lack of proper session management. An attacker could exploit this vulnerability to bypass authentication and gain unauthorized access to the Spectrum Copy Data Management catalog which contains metadata. IBM X-Force ID: 223718.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Copy Data Management | >=2.2.0.0<=2.2.15.0 | |
Linux Linux kernel | ||
<=2.2.0.0-2.2.15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22426 is a vulnerability in IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 that could allow a local attacker to bypass authentication restrictions.
A local attacker can exploit CVE-2022-22426 by taking advantage of the lack of proper session management, bypassing authentication and gaining unauthorized access to the Spectrum Copy Data Management Admin.
CVE-2022-22426 has a severity level of low with a value of 3.3.
IBM Spectrum Copy Data Management Admin versions 2.2.0.0 through 2.2.15.0 are affected by CVE-2022-22426.
To fix CVE-2022-22426, IBM Spectrum Copy Data Management Admin should ensure proper session management to prevent unauthorized access.