IBM Storage Defender - Resiliency Service
cpe:2.3:a:ibm:storage_defender_resiliency_service:*:*:*:*:*:*:*
- >= 2.0.0, <= 2.0.7
A vulnerability in IBM Storage Defender versions 2.0.0 to 2.0.7 has been identified, allowing remote attackers to intercept sensitive information through man-in-the-middle techniques. This issue arises from the defender-sensor-cmd CLI sending network requests over an insecure channel.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information.
Users are advised to upgrade to IBM Storage Defender version 2.0.8 or newer, where the Connection Manager includes the necessary fixes. Instructions for upgrading can be found in the IBM Storage Defender Resiliency Service documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.