#VU64833 Security features bypass in Spectrum Protect Server - CVE-2022-22496
Published: June 30, 2022
Spectrum Protect Server
IBM Corporation
Description
The vulnerability allows a remote attacker on the local network to gain access to sensitive information.
The vulnerability exists due to an error when processing authentication requests. A remote attacker on the local network can bypass security features, configure IBM Spectrum Protect Server to use SESSIONSECURITY=TRANSITIONAL, and gain access to sensitive information.