CVE-2022-40608

HIGH

IBM Spectrum Protect Plus 10.1.6-10.1.11 - Path Traversal via Microsoft File Systems Restore URL

Title source: llm
STIX 2.1

Description

IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID: 235873.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6620209
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/235873

Scores

CVSS v3 7.5
EPSS 0.0070
EPSS Percentile 72.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
ibm/spectrum_protect_plus 10.1.6 - 10.1.11
Published Sep 19, 2022
Tracked Since Feb 18, 2026