cbcvebase.
CVE-2018-1447
published 2018-04-04

CVE-2018-1447: The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function…

PriorityP338high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
0.93%
56.6th percentile
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.

Affected

14 ranges
VendorProductVersion rangeFixed in
ibmspectrum_protect
ibmspectrum_protect
ibmspectrum_protect_for_space_management
ibmspectrum_protect_for_space_management
ibmspectrum_protect_for_space_management7.1.0.0 – 7.1.8.1
ibmspectrum_protect_for_space_management8.1.0.0 – 8.1.4.0
ibmspectrum_protect_for_virtual_environments
ibmspectrum_protect_for_virtual_environments
ibmspectrum_protect_for_virtual_environments7.1.0.0 – 7.1.8.0
ibmspectrum_protect_for_virtual_environments8.1.0.0 – 8.1.4.0
ibmspectrum_protect_snapshot
ibmspectrum_protect_snapshot
ibmspectrum_protect_snapshot
ibmspectrum_protect_snapshot4.1.0.0 – 4.1.6.3

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.