#VU87730 Information disclosure in Storage Protect Plus Container Agent - CVE-2024-27277
Published: March 22, 2024
Vulnerability identifier: #VU87730
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-27277
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Storage Protect Plus Container Agent
Storage Protect Plus Container Agent
Software vendor:
IBM Corporation
IBM Corporation
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to The private key for the IBM Storage Protect Plus Server certificate can be disclosed, undermining the security of the certificate. A local user can gain unauthorized access to sensitive information on the system.
Remediation
Install updates from vendor's website.