First published: Fri Sep 16 2022(Updated: )
Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus. If this generated .crt file is shared, an attacker can obtain the private key information for the uploaded certificate.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | <=10.1.0-10.1.11 | |
IBM Spectrum Protect Plus | <10.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM Spectrum Protect Plus vulnerability is CVE-2022-40234.
Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) are affected by this vulnerability.
The severity of CVE-2022-40234 is medium with a severity value of 5.9.
This vulnerability allows an attacker to obtain the private key if the generated .crt file is shared.
To fix this vulnerability, update IBM Spectrum Protect Plus to version 10.1.12 or later.