CVE-2022-22394

The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrator or node access to the vulnerable server.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:spectrum_protect:8.1.14.100:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-269 NVD-CWE-Other

28 Mar 2022, 17:28

Type Values Removed Values Added
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/222147 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/222147 - VDB Entry, Vendor Advisory
References (CONFIRM) https://www.ibm.com/support/pages/node/6564745 - (CONFIRM) https://www.ibm.com/support/pages/node/6564745 - Patch, Vendor Advisory
CPE cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:spectrum_protect:8.1.14.100:*:*:*:*:*:*:*
First Time Linux linux Kernel
Microsoft windows
Microsoft
Ibm spectrum Protect
Linux
Ibm
Ibm aix
CVSS v2 : unknown
v3 : unknown
v2 : 9.0
v3 : 8.8
CWE CWE-269

21 Mar 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-21 17:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-22394

Mitre link : CVE-2022-22394

CVE.ORG link : CVE-2022-22394


JSON object : View

Products Affected

linux

  • linux_kernel

ibm

  • spectrum_protect
  • aix

microsoft

  • windows