Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m8r8-8368-mvmm

Опубликовано: 20 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID: 235873.

IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID: 235873.

EPSS

Процентиль: 71%
0.00697
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID: 235873.

CVSS3: 5.9
fstec
больше 3 лет назад

Уязвимость функции резервного копирования и восстановления файловых систем Microsoft (Microsoft File Systems) программной платформы защиты данных IBM Spectrum Protect Plus, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 71%
0.00697
Низкий

7.5 High

CVSS3

Дефекты

CWE-22