CVE Tools

Spectrum Protect Server

8 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Spectrum Protect Server, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Spectrum Protect Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Spectrum Protect Server CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-061
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 8 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical225%
  • High225%
  • Medium338%
  • Low113%

Latest CVEs

The 8 most recently published vulnerabilities affecting Spectrum Protect Server.

  1. CVE-2025-3319IBM Spectrum Protect Server authentication bypass8.1
  2. CVE-2022-22496While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susce...6.5
  3. CVE-2022-22487An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative I...9.8
  4. CVE-2022-22485In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on ...9.8
  5. CVE-2022-22394The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit...8.8
  6. CVE-2021-20491IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking during the parsing of commands. By issuing such a command with an improper par...4.4
  7. CVE-2020-4591IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted...3.3
  8. CVE-2018-1788IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.4.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store