CVE-2024-38329

IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by improper validation of user permission. By sending a specially crafted request, an attacker could exploit this vulnerability to change its settings, trigger backups, restore backups, and also delete all previous backups via log rotation. IBM X-Force ID: 294994.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:storage_protect_for_virtual_environments:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:25

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/294994 - Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/294994 - Vendor Advisory
References () https://www.ibm.com/support/pages/node/7157929 - Vendor Advisory () https://www.ibm.com/support/pages/node/7157929 - Vendor Advisory

03 Aug 2024, 12:15

Type Values Removed Values Added
CWE CWE-285

01 Aug 2024, 20:40

Type Values Removed Values Added
CWE CWE-863
CPE cpe:2.3:a:ibm:storage_protect_for_virtual_environments:*:*:*:*:*:*:*:*
First Time Ibm
Ibm storage Protect For Virtual Environments
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/294994 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/294994 - Vendor Advisory
References () https://www.ibm.com/support/pages/node/7157929 - () https://www.ibm.com/support/pages/node/7157929 - Vendor Advisory

20 Jun 2024, 12:44

Type Values Removed Values Added
Summary
  • (es) IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 a 8.1.22.0 podría permitir a un atacante autenticado remoto eludir las restricciones de seguridad causadas por una validación inadecuada del permiso del usuario. Al enviar una solicitud especialmente manipulada, un atacante podría aprovechar esta vulnerabilidad para cambiar su configuración, activar copias de seguridad, restaurar copias de seguridad y también eliminar todas las copias de seguridad anteriores mediante la rotación de registros. ID de IBM X-Force: 294994.

19 Jun 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-19 14:15

Updated : 2024-11-21 09:25


NVD link : CVE-2024-38329

Mitre link : CVE-2024-38329

CVE.ORG link : CVE-2024-38329


JSON object : View

Products Affected

ibm

  • storage_protect_for_virtual_environments
CWE
CWE-863

Incorrect Authorization