Use of a broken or risky cryptographic algorithm in Storage Copy Data Management - CVE-2023-38730
Published: October 4, 2023
Vulnerability identifier: #VU81459
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38730
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the usage of weaker than expected cryptographic algorithms. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
Storage Copy Data Management
IBM Spectrum Copy Data Management
IBM Spectrum Copy Data Management
How to mitigate CVE-2023-38730
Install updates from vendor's website.
Storage Copy Data Management - update to 2.2.20.0
IBM Spectrum Copy Data Management - update to 2.2.20.0
IBM Spectrum Copy Data Management - update to 2.2.20.0