CVE-2022-22496: Medium severity ibm spectrum protect vulnerability
While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942.
Other sources
While a user account for the IBM Spectrum Protect server is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-22496.
What is the severity of CVE-2022-22496?
The severity of CVE-2022-22496 is medium, with a severity score of 6.5.
What software is affected by CVE-2022-22496?
IBM Spectrum Protect Server versions 8.1.0.000 through 8.1.14 are affected by CVE-2022-22496.
What is the risk of using SESSIONSECURITY=TRANSITIONAL in IBM Spectrum Protect Server?
Using SESSIONSECURITY=TRANSITIONAL in IBM Spectrum Protect Server may make it susceptible to an offline dictionary attack.
Where can I find more information about CVE-2022-22496?
You can find more information about CVE-2022-22496 at the following URLs: [IBM X-Force ID: 226942](https://exchange.xforce.ibmcloud.com/vulnerabilities/226942) and [IBM support page](https://www.ibm.com/support/pages/node/6596881).