CVE-2022-22478: Medium severity ibm storage protect backup-archive client vulnerability
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.
Other sources
IBM Spectrum Protect Client stores user credentials in plain clear text which can be read by a local user.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-22478?
CVE-2022-22478 is a vulnerability in IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 that allows a local user to read user credentials stored in plain clear text.
How severe is CVE-2022-22478?
CVE-2022-22478 has a severity rating of 6.2 (Medium).
How can I verify if my IBM Spectrum Protect Client is affected by CVE-2022-22478?
You can check the version of your IBM Spectrum Protect Client. If it is version 8.1.0.0 through 8.1.14.0, then it is affected.
What is the impact of CVE-2022-22478?
The impact of CVE-2022-22478 is that a local user can read user credentials stored in plain clear text, potentially leading to unauthorized access to sensitive information.
How can I mitigate CVE-2022-22478?
To mitigate CVE-2022-22478, upgrade to a version of IBM Spectrum Protect Client that is not affected by the vulnerability or apply any patches or fixes provided by IBM.