#VU94819 Improper Authorization in Storage Protect for Virtual Environments: Data Protection for VMware - CVE-2024-38329

 

#VU94819 Improper Authorization in Storage Protect for Virtual Environments: Data Protection for VMware - CVE-2024-38329

Published: July 29, 2024


Vulnerability identifier: #VU94819
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-38329
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Storage Protect for Virtual Environments: Data Protection for VMware
Software vendor:
IBM Corporation

Description

The vulnerability allows a remote user to bypass security restrictions.

The vulnerability exists due to improper validation of user permission. A remote user can send a specially crafted request and exploit this vulnerability to change settings, trigger backups, restore backups, and also delete all previous backups via log rotation.


Remediation

Install updates from vendor's website.

External links