Vulnerability Details CVE-2022-22496
While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.3%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 3.3
Products affected by CVE-2022-22496
-
cpe:2.3:a:ibm:spectrum_protect_server:8.1.0.0
-
cpe:2.3:a:ibm:spectrum_protect_server:8.1.0.000
-
cpe:2.3:a:ibm:spectrum_protect_server:8.1.1
-
cpe:2.3:a:ibm:spectrum_protect_server:8.1.10.000
-
cpe:2.3:a:ibm:spectrum_protect_server:8.1.2
-
cpe:2.3:a:ibm:spectrum_protect_server:8.1.3
-
cpe:2.3:a:ibm:spectrum_protect_server:8.1.4
-
cpe:2.3:a:ibm:spectrum_protect_server:8.1.5
-
cpe:2.3:a:ibm:spectrum_protect_server:8.1.5.100
-
cpe:2.3:a:ibm:spectrum_protect_server:8.1.6
-
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-