PT-2018-12539 · Ibm · Ibm Spectrum Protect Snapshot+3

Published

2018-04-04

·

Updated

2019-10-03

·

CVE-2018-1447

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect versions 7.1 through 7.2 IBM Spectrum Protect Snapshot versions 4.1.3, 4.1.4, 4.1.6
Description The GSKit CMS KDB logic fails to salt the hash function, resulting in weaker than expected protection of passwords. This weakness may allow a weak password to be recovered.
Recommendations For IBM Spectrum Protect versions 7.1 and 7.2, update to a newer version and change passwords to ensure they are stored more securely. For IBM Spectrum Protect Snapshot versions 4.1.3, 4.1.4, and 4.1.6, update to a newer version and change passwords to ensure they are stored more securely.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1447

Affected Products

Gskit
Ibm Aix
Ibm Spectrum Protect
Ibm Spectrum Protect Snapshot