CVE-2024-22314: IBM Storage Defender - Resiliency Service information disclosure
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM Storage Defender - Resiliency Service uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22314?
The severity of CVE-2024-22314 is classified as critical due to the potential exposure of sensitive information.
How do I fix CVE-2024-22314?
To fix CVE-2024-22314, upgrade IBM Storage Defender - Resiliency Service to version 2.0.13 or later where stronger cryptographic algorithms are implemented.
What are the risks associated with CVE-2024-22314?
The risks associated with CVE-2024-22314 include unauthorized decryption of sensitive data, leading to potential data breaches.
Which versions of IBM Storage Defender - Resiliency Service are affected by CVE-2024-22314?
Versions 2.0.0 through 2.0.12 of IBM Storage Defender - Resiliency Service are affected by CVE-2024-22314.
Who is impacted by CVE-2024-22314?
Organizations using affected versions of IBM Storage Defender - Resiliency Service may be impacted by CVE-2024-22314.