First published: Wed Jun 29 2022(Updated: )
While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Server | >=8.1.0.000<=8.1.14 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
<=8.1.0.000-8.1.14.xxx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-22496.
The severity of CVE-2022-22496 is medium, with a severity score of 6.5.
IBM Spectrum Protect Server versions 8.1.0.000 through 8.1.14 are affected by CVE-2022-22496.
Using SESSIONSECURITY=TRANSITIONAL in IBM Spectrum Protect Server may make it susceptible to an offline dictionary attack.
You can find more information about CVE-2022-22496 at the following URLs: [IBM X-Force ID: 226942](https://exchange.xforce.ibmcloud.com/vulnerabilities/226942) and [IBM support page](https://www.ibm.com/support/pages/node/6596881).