CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

ibm

spectrum_protect_plus

44 known vulnerabilities · sorted by CVSS score

CVE-2020-4216
CRITICAL9.8

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 175066.

ibm / spectrum_protect_plus
Network
Published Jun 15, 2020
Page 1 of 3
CVE-2020-4854
CRITICAL9.8

IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 190454.

ibm / spectrum_protect_plus
Network
Published Nov 23, 2020
CVE-2020-4208
CRITICAL9.8

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975.

ibm / spectrum_protect_plus
Network
Published Mar 31, 2020
CVE-2020-4469
CRITICAL9.8

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. This vulnerability is due to an incomplete fix for CVE-2020-4211. IBM X-Force ID: 181724.

ibm / spectrum_protect_plus
Network
Published Jun 15, 2020
CVE-2021-39063
CRITICAL9.1

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force ID: 214956.

ibm / spectrum_protect_plus
Network
Published Dec 13, 2021
CVE-2020-4242
HIGH8.8

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175419.

ibm / spectrum_protect_plus+1
Network
Published Mar 31, 2020
CVE-2020-4241
HIGH8.8

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175418.

ibm / spectrum_protect_plus+1
Network
Published Mar 31, 2020
CVE-2020-4206
HIGH8.8

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input. IBM X-Force ID: 174966.

ibm / spectrum_protect_plus
Network
Published Mar 31, 2020
CVE-2021-39057
HIGH8.1

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 214616.

ibm / spectrum_protect_plus
Network
Published Dec 13, 2021
CVE-2020-4470
HIGH8.0

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. IBM X-Force ID: 181725.

ibm / spectrum_protect_plus
Network
Published Jun 15, 2020
CVE-2020-4703
HIGH8.0

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.

ibm / spectrum_protect_plus
Network
Published Sep 15, 2020
CVE-2021-29694
HIGH7.5

IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258.

ibm / spectrum_protect_plus
Network
Published Apr 26, 2021
CVE-2022-22354
HIGH7.5

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.

ibm / spectrum_copy_data_management+1
Network
Published Mar 14, 2022
CVE-2022-22396
HIGH7.5

Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key or certificate are not printed. IBM X-Force ID: 222231.

ibm / spectrum_protect_plus
Network
Published Jun 6, 2022
CVE-2020-5018
HIGH7.5

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654.

ibm / spectrum_protect_plus
Network
Published Jan 8, 2021
CVE-2020-4214
HIGH7.5

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input. IBM X-Force ID: 175026.

ibm / spectrum_protect_plus
Network
Published Mar 31, 2020
CVE-2022-40608
HIGH7.5

IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID: 235873.

ibm / spectrum_protect_plus
Network
Published Sep 19, 2022
CVE-2020-5023
HIGH7.5

IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to excess resource consumption. IBM X-Force ID: 193659.

ibm / spectrum_protect_plus
Network
Published Feb 10, 2021
CVE-2019-4652
HIGH7.1

IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170963.

ibm / spectrum_protect_plus
Local
Published Nov 12, 2019
CVE-2020-4497
MEDIUM6.8

IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106.

ibm / spectrum_protect_plus
Network
Published Dec 14, 2022