CVE-2024-22312: IBM Storage Defender - Resiliency Service information disclosure
IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.
Other sources
IBM Storage Defender - Resiliency Service stores user credentials in plain clear text which can be read by a local user.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22312?
CVE-2024-22312 has a high severity due to the risk of sensitive user credentials being exposed in plain text.
How do I fix CVE-2024-22312?
To fix CVE-2024-22312, upgrade the IBM Storage Defender - Resiliency Service to a version beyond 2.0.0 where this vulnerability is addressed.
What impact does CVE-2024-22312 have on my system?
CVE-2024-22312 allows local users to read stored user credentials, potentially leading to unauthorized access.
Which versions of IBM Storage Defender are affected by CVE-2024-22312?
CVE-2024-22312 affects IBM Storage Defender - Resiliency Service version 2.0.0 and earlier.
Is there a known exploit for CVE-2024-22312?
As of now, there are no publicly available exploits specifically targeting CVE-2024-22312.