IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7168640 |
History
Mon, 30 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ibm storage Defender
|
|
Weaknesses | CWE-295 | |
CPEs | cpe:2.3:a:ibm:storage_defender:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ibm storage Defender
|
Tue, 24 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 24 Sep 2024 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system. | |
Title | IBM Storage Defender improper certificate validation | |
First Time appeared |
Ibm
Ibm storage Defender Resiliency Service |
|
Weaknesses | CWE-297 | |
CPEs | cpe:2.3:a:ibm:storage_defender_resiliency_service:2.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_defender_resiliency_service:2.0.7:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm storage Defender Resiliency Service |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2024-09-24T10:24:43.447Z
Updated: 2024-09-24T13:48:52.386Z
Reserved: 2024-06-13T21:43:59.169Z
Link: CVE-2024-38324
Vulnrichment
Updated: 2024-09-24T13:48:47.991Z
NVD
Status : Analyzed
Published: 2024-09-25T01:15:40.493
Modified: 2024-09-30T14:10:18.597
Link: CVE-2024-38324
Redhat
No data.