CVE-2022-22396

Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key or certificate are not printed. IBM X-Force ID: 222231.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:spectrum_protect_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:-:*:*:*:*:*:*:*

History

14 Jun 2022, 15:46

Type Values Removed Values Added
First Time Linux
Linux linux Kernel
Ibm spectrum Protect Plus
Ibm
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CPE cpe:2.3:a:ibm:spectrum_protect_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:-:*:*:*:*:*:*:*
CWE CWE-522
References (CONFIRM) https://www.ibm.com/support/pages/node/6591505 - (CONFIRM) https://www.ibm.com/support/pages/node/6591505 - Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/222231 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/222231 - VDB Entry, Vendor Advisory

06 Jun 2022, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-06 19:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-22396

Mitre link : CVE-2022-22396

CVE.ORG link : CVE-2022-22396


JSON object : View

Products Affected

ibm

  • spectrum_protect_plus

linux

  • linux_kernel
CWE
CWE-522

Insufficiently Protected Credentials