Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system
Vulnerability Description
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentication code paths, and does not properly validate authentication responses, which may allow an unauthenticated attacker to establish a trusted session and access protected services. This vulnerability affects client components across multiple versions and may allow an attacker to impersonate legitimate clients, potentially leading to unauthorized access to system resources.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
IBM Storage Protect Client 信任管理问题漏洞
Vulnerability Description
IBM storage protect client是美国IBM公司的一个数据保护客户端软件。 IBM Storage Protect Client和IBM Storage Protect Snapshot For Windows存在信任管理问题漏洞,该漏洞源于FlashCopy Manager(FCM)身份验证机制中使用硬编码凭证,且未正确验证身份验证响应,可能导致远程攻击者绕过身份验证、建立可信会话并访问受保护服务,进而冒充合法客户端导致未授权访问系统资源。
CVSS Information
N/A
Vulnerability Type
N/A