CVE Vulnerabilities

CVE-2022-22484

Cleartext Storage of Sensitive Information

Published: May 17, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browsers application command history. By accessing browser history, an attacker could exploit this vulnerability to obtain other user accounts passwords. IBM X-Force ID: 226322.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Spectrum_protect Ibm 8.1.12.000 (including) 8.1.14 (excluding)

Potential Mitigations

References