CVE Published: 19/09/2022 |
CVE Updated: 17/09/2024 |
CVE Year: 2022 Source: ibm |
Vendor: IBM |
Product: Spectrum Protect Plus Status : PUBLISHED
CVE-2022-40608 Description
IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID: 235873.