First published: Thu Jan 26 2023(Updated: )
IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Virtualize | =8.3.0.0 | |
IBM Spectrum Virtualize | =8.4.0.0 | |
IBM Spectrum Virtualize | =8.5.0.0 | |
IBM Spectrum Virtualize | <=8.3 | |
IBM Spectrum Virtualize | <=8.4 | |
IBM Spectrum Virtualize | <=8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43870 is medium with a CVSS score of 6.5.
CVE-2022-43870 is a vulnerability in IBM Spectrum Virtualize 8.3, 8.4, and 8.5 that could disclose SNMPv3 server credentials to an authenticated user in log files.
IBM Spectrum Virtualize versions 8.3, 8.4, and 8.5 are affected by CVE-2022-43870.
An authenticated user can exploit CVE-2022-43870 by accessing log files that contain SNMPv3 server credentials.
Yes, you can find more information about CVE-2022-43870 at the following references: [IBM X-Force ID: 239540](https://exchange.xforce.ibmcloud.com/vulnerabilities/239540) and [IBM Support](https://www.ibm.com/support/pages/node/6858045).