Fiche vulnérabilité
CVE-2022-22354 : faille moyenne IBM Spectrum Copy Data Management (CVSS 6.2)
Description
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.
En bref
- Sévérité
- Moyenne (CVSS 6.2)
- Vecteur CVSS
- CVSS:3.0/S:U/UI:N/AC:L/AV:L/I:N/A:H/PR:N/C:N/RL:O/E:U/RC:C
- Exploitation active
- Non signalée par la CISA
- Publication
- 14 mars 2022
- Dernière mise à jour
- 17 sept. 2024
Produits concernés
- IBM Spectrum Copy Data Management
- IBM Spectrum Protect Plus