#VU73998 Insufficiently protected credentials in IBM Spectrum Protect Plus - CVE-2023-27863
Published: March 23, 2023
IBM Spectrum Protect Plus
IBM Corporation
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to IBM Spectrum Protect Plus for Db2 and Oracle with transport encryption enabled can expose SMB credentials to access vSnap data stores. A remote privileged user can obtain SMB credentials that may be used to access vSnap data stores.