CVE-2018-1447
published 2018-04-04CVE-2018-1447: The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function…
PriorityP338high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
0.93%
56.6th percentile
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | spectrum_protect | — | — |
| ibm | spectrum_protect | — | — |
| ibm | spectrum_protect_for_space_management | — | — |
| ibm | spectrum_protect_for_space_management | — | — |
| ibm | spectrum_protect_for_space_management | 7.1.0.0 – 7.1.8.1 | — |
| ibm | spectrum_protect_for_space_management | 8.1.0.0 – 8.1.4.0 | — |
| ibm | spectrum_protect_for_virtual_environments | — | — |
| ibm | spectrum_protect_for_virtual_environments | — | — |
| ibm | spectrum_protect_for_virtual_environments | 7.1.0.0 – 7.1.8.0 | — |
| ibm | spectrum_protect_for_virtual_environments | 8.1.0.0 – 8.1.4.0 | — |
| ibm | spectrum_protect_snapshot | — | — |
| ibm | spectrum_protect_snapshot | — | — |
| ibm | spectrum_protect_snapshot | — | — |
| ibm | spectrum_protect_snapshot | 4.1.0.0 – 4.1.6.3 | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
http://www.ibm.com/support/docview.wss?uid=swg22014669http://www.ibm.com/support/docview.wss?uid=swg22014957http://www.ibm.com/support/docview.wss?uid=swg22015066http://www.ibm.com/support/docview.wss?uid=swg22015071http://www.securityfocus.com/bid/104511http://www.securitytracker.com/id/1041012https://exchange.xforce.ibmcloud.com/vulnerabilities/139972http://www.ibm.com/support/docview.wss?uid=swg22014669http://www.ibm.com/support/docview.wss?uid=swg22014957http://www.ibm.com/support/docview.wss?uid=swg22015066http://www.ibm.com/support/docview.wss?uid=swg22015071http://www.securityfocus.com/bid/104511http://www.securitytracker.com/id/1041012https://exchange.xforce.ibmcloud.com/vulnerabilities/139972
2018-04-04
Published