Information disclosure in Storage Protect Plus Container Agent - CVE-2024-27277

 

Information disclosure in Storage Protect Plus Container Agent - CVE-2024-27277

Published: March 22, 2024


Vulnerability identifier: #VU87730
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27277
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to The private key for the IBM Storage Protect Plus Server certificate can be disclosed, undermining the security of the certificate. A local user can gain unauthorized access to sensitive information on the system.


Affected software

Storage Protect Plus Container Agent
Storage Protect Plus Server

How to mitigate CVE-2024-27277

Install updates from vendor's website.

Storage Protect Plus Server - update to 10.1.16.1

External References

Related Security Bulletins