CVE Vulnerabilities

CVE-2022-22484

Cleartext Storage of Sensitive Information

Published: May 17, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browsers application command history. By accessing browser history, an attacker could exploit this vulnerability to obtain other user accounts passwords. IBM X-Force ID: 226322.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

NameVendorStart VersionEnd Version
Spectrum_protectIbm8.1.12.000 (including)8.1.14 (excluding)

Potential Mitigations

References