CVE-2020-5022

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:spectrum_protect_plus:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

11 Jan 2021, 20:05

Type Values Removed Values Added
References (CONFIRM) https://www.ibm.com/support/pages/node/6398754 - (CONFIRM) https://www.ibm.com/support/pages/node/6398754 - Patch, Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/193658 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/193658 - VDB Entry, Vendor Advisory
CWE CWE-200
CPE cpe:2.3:a:ibm:spectrum_protect_plus:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3

08 Jan 2021, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-01-08 19:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-5022

Mitre link : CVE-2020-5022

CVE.ORG link : CVE-2020-5022


JSON object : View

Products Affected

ibm

  • spectrum_protect_plus

linux

  • linux_kernel
CWE
CWE-306

Missing Authentication for Critical Function

CWE-862

Missing Authorization