CVE-2024-27277: IBM Storage Protect Plus Server information disclosure
The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certificate. IBM X-Force ID: 285205.
Other sources
The private key for the IBM Storage Protect Plus Server certificate can be disclosed, undermining the security of the certificate.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27277?
The severity of CVE-2024-27277 is considered significant due to the potential exposure of the private key.
How do I fix CVE-2024-27277?
To fix CVE-2024-27277, users should upgrade IBM Storage Protect Plus Server to version 10.1.17 or later.
What versions of IBM Storage Protect Plus Server are affected by CVE-2024-27277?
CVE-2024-27277 affects IBM Storage Protect Plus Server versions 10.1.0 through 10.1.16.
What is the impact of CVE-2024-27277?
CVE-2024-27277 can lead to a compromise of the security of encrypted communications by disclosing the private key.
Is there a workaround for CVE-2024-27277?
There are no specific workarounds for CVE-2024-27277; the recommended action is to upgrade to a secure version.