IT

Tracker / CVE-2020-5021

CVE-2020-5021

Medium 4.4

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657.

Affected products and versions

ibm spectrum_protect_plus · 10.1.0 → 10.1.7

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References