CVE-2020-4591

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
28/08/2020
Last modified:
21/07/2021

Description

IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted container pool. IBM X-Force ID: 184746.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:spectrum_protect_server:*:*:*:*:*:*:*:* 8.1.0.000 (including) 8.1.10.000 (including)
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*