Improper Restriction of Excessive Authentication Attempts in IBM Spectrum Protect Operations Center - CVE-2022-22485

 

Improper Restriction of Excessive Authentication Attempts in IBM Spectrum Protect Operations Center - CVE-2022-22485

Published: June 20, 2022


Vulnerability identifier: #VU64499
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22485
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper restriction of excessive authentication attempts. A remote unauthenticated attacker can exploit this vulnerability using brute force techniques to gain unauthorized administrative access to the IBM Spectrum Protect Server.


Affected software

IBM Spectrum Protect Operations Center
Spectrum Protect Server

How to mitigate CVE-2022-22485

Install updates from vendor's website.

Spectrum Protect Server - update to 8.1.14.100

External References

Related Security Bulletins