First published: Wed Apr 16 2025(Updated: )
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Storage Defender Resiliency Service | >=2.0.0<=2.0.12 | |
IBM Storage Defender Resiliency Service | <=2.0.0 - 2.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-22314 is classified as critical due to the potential exposure of sensitive information.
To fix CVE-2024-22314, upgrade IBM Storage Defender - Resiliency Service to version 2.0.13 or later where stronger cryptographic algorithms are implemented.
The risks associated with CVE-2024-22314 include unauthorized decryption of sensitive data, leading to potential data breaches.
Versions 2.0.0 through 2.0.12 of IBM Storage Defender - Resiliency Service are affected by CVE-2024-22314.
Organizations using affected versions of IBM Storage Defender - Resiliency Service may be impacted by CVE-2024-22314.