IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7178587 | vendor advisory |