CVE-2019-4385
Summary
| CVE | CVE-2019-4385 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-19 14:15:00 UTC |
| Updated | 2023-01-30 16:51:00 UTC |
| Description | IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Spectrum Protect Plus | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Spectrum Protect Plus CVE-2019-4385 Local Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| Security Bulletin: Password exposure via job log in IBM Spectrum Protect Plus (CVE-2019-4385) | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.