Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-22487

Опубликовано: 30 июн. 2022
Источник: nvd
CVSS3: 5.9
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to both the IBM Spectrum Protect storage agent and the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 with which it communicates. IBM X-Force ID: 226326.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:ibm:spectrum_protect_server:*:*:*:*:*:*:*:*
Версия от 8.1.0.000 (включая) до 8.1.14 (включая)

Одно из

cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 51%
0.00276
Низкий

5.9 Medium

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to both the IBM Spectrum Protect storage agent and the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 with which it communicates. IBM X-Force ID: 226326.

EPSS

Процентиль: 51%
0.00276
Низкий

5.9 Medium

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-307