CVE-2018-1447
Summary
| CVE | CVE-2018-1447 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-04 18:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972. |
Risk And Classification
Problem Types: CWE-916
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Spectrum Protect For Space Management | All | All | All | All |
| Application | Ibm | Spectrum Protect For Space Management | All | All | All | All |
| Application | Ibm | Spectrum Protect For Virtual Environments | All | All | All | All |
| Application | Ibm | Spectrum Protect For Virtual Environments | All | All | All | All |
| Application | Ibm | Spectrum Protect Snapshot | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: Multiple vulnerabilities in the IBM GSKit component of IBM Spectrum Protect (formerly Tivoli Storage Manager) Client - United States | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| Multiple IBM Products CVE-2018-1447 Local Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| IBM Security Bulletin: Multiple vulnerabilities in the IBM GSKit component of IBM Spectrum Protect Snapshot (formerly Tivoli Storage FlashCopy Manager) for VMware - United States | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| IBM Security Bulletin: Multiple vulnerabilities in the IBM GSKit component of IBM Spectrum Protect (formerly Tivoli Storage Manager) for Virtual Environments: Data Protection for VMware - United States | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| IBM Security Network Protection GSKit Flaws Let Local Users Obtain Passwords and Other Sensitive Information and Deny Service - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Security Bulletin: Multiple vulnerabilities in the IBM GSKit component of IBM Spectrum Protect (formerly Tivoli Storage Manager) for Space Management | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.