IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6398754 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/193658 | vdb entry vendor advisory |