This page lists publicly disclosed CVE vulnerabilities affecting ibm storage_defender (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-38325 | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | [email protected] | 5.9 | 0.05% | 2025-01-27 | 2025-08-14 |
| CVE-2024-38324 | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system. | [email protected] | 5.9 | 0.06% | 2024-09-25 | 2024-09-30 |
| CVE-2024-25031 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute force account credentials. IBM X-Force ID: 281678. | [email protected] | 6.5 | 0.05% | 2024-06-28 | 2024-11-21 |