VulnerabilityModified
CVE-2019-4385
This can result in an attacker gaining access to sensitive information as well as vSnap.
MEDIUM 6.5EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- ibm/spectrum protect plus
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=ibm10886099Patch, Vendor Advisory
- http://www.securityfocus.com/bid/108899Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/162173VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10886099Patch, Vendor Advisory
- http://www.securityfocus.com/bid/108899Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/162173VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.