CVE-2018-1447

CWE-9164 documents4 sources
Severity
8.1HIGH
EPSS
0.1%
top 76.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateMay 13

Description

The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 1.4 | Impact: 3.6

Affected Packages6 packages

NVDibm/spectrum_protect_snapshot4.1.0.04.1.6.3
CVEListV5ibm/spectrum_protect_snapshot4.1.3, 4.1.4, 4.1.6+2
NVDibm/spectrum_protect7.1.0.07.1.8.1+1
CVEListV5ibm/spectrum_protect7.1, 8.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m7f9-w9g7-x6f7: The GSKit (IBM Spectrum Protect 72022-05-13
CVEList
CVE-2018-1447: The GSKit (IBM Spectrum Protect 72018-04-04

💬Community

1
Bugzilla
CVE-2018-16427 opensc: Out of bounds reads handling responses from smartcards2018-09-12
CVE-2018-1447 (HIGH CVSS 8.1) | The GSKit (IBM Spectrum Protect 7.1 | cvebase.io