SB2023032370 - Insufficiently protected credentials in IBM Spectrum Protect Plus



SB2023032370 - Insufficiently protected credentials in IBM Spectrum Protect Plus

Published: March 23, 2023

Security Bulletin ID SB2023032370
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficiently protected credentials (CVE-ID: CVE-2023-27863)

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to IBM Spectrum Protect Plus for Db2 and Oracle with transport encryption enabled can expose SMB credentials to access vSnap data stores. A remote privileged user can obtain SMB credentials that may be used to access vSnap data stores.


Remediation

Install update from vendor's website.