Information disclosure in IBM Spectrum Protect Plus - CVE-2019-4703

 

Information disclosure in IBM Spectrum Protect Plus - CVE-2019-4703

Published: April 3, 2020


Vulnerability identifier: #VU26560
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-4703
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the user id and password may be exposed when protecting Microsoft SQL or Microsoft Exchange. A remote attacker on the local network with intimate knowledge of the system can gain unauthorized access to sensitive information on the system.


Affected software

IBM Spectrum Protect Plus

How to mitigate CVE-2019-4703

Install updates from vendor's website.

IBM Spectrum Protect Plus - update to 10.1.5.1

External References

Related Security Bulletins