CVE-2022-22396 is a critical information disclosure vulnerability affecting IBM Spectrum Protect Plus versions 10.1.0.0 through 10.1.9.3. In specific scenarios, sensitive credentials for remote vSnap, offload targets, or VADP are inadvertently logged in clear text within the virgo log file. This vulnerability carries a CVSS v3.1 score of 7.5 (HIGH), indicating that an unauthenticated attacker could remotely access these logs and compromise credentials, leading to unauthorized access to protected data. While the vulnerability is severe, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.1.0, < 10.1.10CPE matchmatch criteria | cpe:2.3:a:ibm:spectrum_protect_plus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.