First published: Fri May 13 2022(Updated: )
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By accessing browser history, an attacker could exploit this vulnerability to obtain other user accounts' passwords. IBM X-Force ID: 226322.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect | >=8.1.12.000<8.1.14 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
<=8.1.12.000-8.1.13.xxx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22484 is a vulnerability in IBM Spectrum Protect Operations Center.
CVE-2022-22484 allows a local attacker to obtain sensitive information by accessing the browser's application command history.
IBM Spectrum Protect Operations Center versions 8.1.12 and 8.1.13 are affected by CVE-2022-22484.
The severity of CVE-2022-22484 is medium.
To fix CVE-2022-22484, it is recommended to upgrade to a version of IBM Spectrum Protect Operations Center that is not affected by the vulnerability.