Known vulnerabilities in IBM Spectrum Virtualize
Vendor:
IBM Corporation
Software:
IBM Spectrum Virtualize
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_spectrum_virtualize:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
14
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (14)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU89605 - Information Exposure Through Log Files CVE-2022-43870 |
CWE-532 | Low | 8.3.1.9, 8.4.0.10, 8.5.0.7, 8.5.2.3, 8.5.3.0 | 17.05.2024 |
SB2024051704 |
||
| #VU89594 - Permissions, Privileges, and Access Controls CVE-2022-43873 |
CWE-264 | Medium | 8.2.1.17, 8.3.1.9, 8.4.0.10, 8.5.0.7, 8.5.2.3, 8.5.3.0 | 16.05.2024 |
SB2024051622 |
||
| #VU82192 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') CVE-2023-25681 |
CWE-90 | Medium | 8.5.0.7, 8.5.2.3, 8.5.4.0 | 18.10.2023 |
SB2023101812 |
||
| #VU81116 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2022-39167 |
CWE-300 | Medium | 7.8.1.16, 8.2.1.16, 8.3.1.9, 8.5.0.6, 8.5.2.0 | 26.09.2023 |
SB2023092625 |
||
| #VU75508 - Exposure of sensitive information to an unauthorized actor CVE-2023-30441 |
CWE-200 | Medium | 8.2.1.17, 8.3.1.9, 8.4.0.10, 8.5.0.7, 8.5.2.3, 8.5.4.0 | 26.04.2023 |
SB2023042618 SB2023042749 SB2023050107 and 41 more |
||
| #VU64079 - Missing release of memory after effective lifetime CVE-2022-1012 |
CWE-401 | Medium | 8.4.0.10, 8.5.0.7, 8.5.2.3, 8.5.3.0 | 08.06.2022 |
SB2022060827 SB2022061417 SB2022062437 and 75 more |
||
| #VU63668 - Exposure of sensitive information to an unauthorized actor CVE-2021-45485 |
CWE-200 | Medium | 8.4.0.10, 8.5.0.7, 8.5.2.3, 8.5.3.0 | 25.05.2022 |
SB2022022237 SB2022062928 SB2022062931 and 26 more |
||
| #VU63577 - Exposure of sensitive information to an unauthorized actor CVE-2021-45486 |
CWE-200 | Medium | 8.4.0.10, 8.5.0.7, 8.5.2.3, 8.5.3.0 | 24.05.2022 |
SB2022062928 SB2022062931 SB2022070643 and 26 more |
||
| #VU63299 - Error Handling CVE-2022-25762 |
CWE-388 | Medium | - | 17.05.2022 |
SB2022051715 SB2022071173 SB2022072094 and 14 more |
||
| #VU61671 - Memory corruption CVE-2018-25032 |
CWE-119 | Medium | 7.8.1.16, 8.2.1.16, 8.3.1.8, 8.4.0.7, 8.5.0.5, 8.5.2.0 | 28.03.2022 |
SB2022032844 SB2022032845 SB2022033018 and 192 more |
||
| #VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-0778 |
CWE-835 | Medium | 7.8.1.15, 8.2.1.16, 8.3.1.7, 8.4.0.9, 8.5.0.1, 8.5.2.0 | 15.03.2022 |
SB2022031520 SB2022031522 SB2022031611 and 238 more |
||
| #VU57487 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2021-35550 |
CWE-300 | Medium | 7.8.1.15, 8.2.1.16, 8.3.1.7, 8.4.0.9, 8.5.0.1, 8.5.2.0 | 19.10.2021 |
SB2021101939 SB2021101940 SB2021102101 and 102 more |
||
| #VU57496 - Improper input validation CVE-2021-35603 |
CWE-20 | Low | 7.8.1.15, 8.2.1.16, 8.3.1.7, 8.4.0.9, 8.5.0.1, 8.5.2.0 | 19.10.2021 |
SB2021101939 SB2021101940 SB2021102101 and 112 more |
||
| #VU45746 - Improper Access Control CVE-2020-4686 |
CWE-284 | Medium | - | 17.08.2020 |
SB2020081708 SB2023030103 |