CVE-2023-27863: IBM Spectrum Protect Plus Server information disclosure
IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325.
Other sources
IBM Spectrum Protect Plus Server, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27863?
The severity of CVE-2023-27863 is medium with a severity value of 4.9.
How can an elevated user obtain SMB credentials in IBM Spectrum Protect Plus Server under specific configurations?
In IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, an elevated user can obtain SMB credentials.
What are the affected software versions of IBM Spectrum Protect Plus Server?
IBM Spectrum Protect Plus Server version 10.1.13 is affected.
Is Linux Linux kernel vulnerable to CVE-2023-27863?
No, Linux Linux kernel is not vulnerable to CVE-2023-27863.
Where can I find more information about CVE-2023-27863?
More information about CVE-2023-27863 can be found at the following references: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/249325) and [link2](https://www.ibm.com/support/pages/node/6965812).