CVE-2022-43870: IBM Spectrum Virtualize information disclosure
IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43870?
The severity of CVE-2022-43870 is medium with a CVSS score of 6.5.
What is the vulnerability description of CVE-2022-43870?
CVE-2022-43870 is a vulnerability in IBM Spectrum Virtualize 8.3, 8.4, and 8.5 that could disclose SNMPv3 server credentials to an authenticated user in log files.
Which versions of IBM Spectrum Virtualize are affected by CVE-2022-43870?
IBM Spectrum Virtualize versions 8.3, 8.4, and 8.5 are affected by CVE-2022-43870.
How can an authenticated user exploit CVE-2022-43870?
An authenticated user can exploit CVE-2022-43870 by accessing log files that contain SNMPv3 server credentials.
Are there any references available for CVE-2022-43870?
Yes, you can find more information about CVE-2022-43870 at the following references: [IBM X-Force ID: 239540](https://exchange.xforce.ibmcloud.com/vulnerabilities/239540) and [IBM Support](https://www.ibm.com/support/pages/node/6858045).