Description
IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by improper validation of user permission. By sending a specially crafted request, an attacker could exploit this vulnerability to change its settings, trigger backups, restore backups, and also delete all previous backups via log rotation. IBM X-Force ID: 294994.
Published: 2024-06-19
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-37268 IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by improper validation of user permission. By sending a specially crafted request, an attacker could exploit this vulnerability to change its settings, trigger backups, restore backups, and also delete all previous backups via log rotation. IBM X-Force ID: 294994.
History

No history.

Subscriptions

Ibm Storage Protect For Virtual Environments
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-03T11:22:42.851Z

Reserved: 2024-06-13T21:43:59.170Z

Link: CVE-2024-38329

cve-icon Vulnrichment

Updated: 2024-08-02T04:04:25.072Z

cve-icon NVD

Status : Modified

Published: 2024-06-19T14:15:13.723

Modified: 2024-11-21T09:25:22.867

Link: CVE-2024-38329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses