PT-2018-14155 · Ibm · Ibm Spectrum Protect Plus
Published
2018-09-26
·
Updated
2019-10-09
·
CVE-2018-1768
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect Plus versions 10.1.0 through 10.1.1
Description
The issue could disclose sensitive information when an authorized user executes a test operation. The
user id and password may be displayed in plain text within an instrumentation log file.Recommendations
For versions 10.1.0 and 10.1.1, consider restricting access to the instrumentation log file to minimize the risk of sensitive information disclosure until a fix is available.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Protect Plus