Aller au contenu

Fiche vulnérabilité

CVE-2022-22354 : faille moyenne IBM Spectrum Copy Data Management (CVSS 6.2)

Description

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.

En bref

Sévérité
Moyenne (CVSS 6.2)
Vecteur CVSS
CVSS:3.0/S:U/UI:N/AC:L/AV:L/I:N/A:H/PR:N/C:N/RL:O/E:U/RC:C
Exploitation active
Non signalée par la CISA
Publication
14 mars 2022
Dernière mise à jour
17 sept. 2024

Produits concernés

  • IBM Spectrum Copy Data Management
  • IBM Spectrum Protect Plus

Références

Rechercher une autre vulnérabilité dans la base CVE