CVE-2023-47148: IBM Storage Protect Plus Server information disclosure
IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 270599.
Other sources
IBM Storage Protect Plus Server Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47148?
CVE-2023-47148 has a moderate severity, allowing remote attackers to access sensitive information.
How do I fix CVE-2023-47148?
To fix CVE-2023-47148, upgrade IBM Storage Protect Plus Server to the latest version beyond 10.1.15.2.
What makes CVE-2023-47148 vulnerable?
CVE-2023-47148 is vulnerable due to improper validation of unsecured endpoints, permitting potential information disclosure.
Which versions of IBM Storage Protect Plus are affected by CVE-2023-47148?
CVE-2023-47148 affects IBM Storage Protect Plus Server versions 10.1.0 through 10.1.15.2.
What types of attacks can exploit CVE-2023-47148?
Exploitation of CVE-2023-47148 can facilitate further attacks aimed at gaining unauthorized access to sensitive information.