Spectrum Copy Data Management
Vendor:
First CVE: Dec 13, 2021 · Active for 4 years
18
Total CVEs
More Total CVEs than 94% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spectrum Copy Data Management over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 13, 2021
4 years ago
Most Recent CVE
Aug 27, 2023
1,066 days ago
CVE Severity & Scoring
Spectrum Copy Data Management18 CVEs
44%
39%
11%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (11.1%)
Network16 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (66.7%)
Unknown0 (0.0%)
Required6 (33.3%)
Privileges Required
Low5 (27.8%)
High1 (5.6%)
None12 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39065CRITICAL IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input | Dec 13, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-39052CRITICAL IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523. | Dec 13, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-22479HIGH IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr | Jun 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-22354HIGH IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a S | Mar 14, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-39064HIGH IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Ad | Dec 13, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-39058HIGH IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X- | Dec 13, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-39053HIGH IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to obtain sensitive information, caused by the improper handling of requests for Spectrum Copy Da | Dec 13, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-38947HIGH IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X- | Dec 13, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-38730HIGH IBM Storage Copy Data Management 2.2.0.0 through 2.2.19.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | Aug 27, 2023 | 7.5 | 22 | NO | NO |
CVE-2021-39051MEDIUM IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A rem | Mar 14, 2022 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Spectrum Copy Data Management
Top CWEs
Versions
No cataloged versions.