SB2023032370 - Insufficiently protected credentials in IBM Spectrum Protect Plus
Published: March 23, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficiently protected credentials (CVE-ID: CVE-2023-27863)
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to IBM Spectrum Protect Plus for Db2 and Oracle with transport encryption enabled can expose SMB credentials to access vSnap data stores. A remote privileged user can obtain SMB credentials that may be used to access vSnap data stores.
Remediation
Install update from vendor's website.