CVE-2017-1378
Last modified
CVE-2017-1378 is a vulnerability of currently unknown severity. IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tivoli Storage Manager | 6.1 |
| Ibm | Tivoli Storage Manager | 6.1.0 |
| Ibm | Tivoli Storage Manager | 6.1.1 |
| Ibm | Tivoli Storage Manager | 6.1.2 |
| Ibm | Tivoli Storage Manager | 6.1.3 |
| Ibm | Tivoli Storage Manager | 6.1.4 |
| Ibm | Tivoli Storage Manager | 6.1.5 |
| Ibm | Tivoli Storage Manager | 6.1.5.4 |
| Ibm | Tivoli Storage Manager | 6.1.5.5 |
| Ibm | Tivoli Storage Manager | 6.1.5.6 |
| Ibm | Tivoli Storage Manager | 6.2.0 |
| Ibm | Tivoli Storage Manager | 6.2.1 |
| Ibm | Tivoli Storage Manager | 6.2.2 |
| Ibm | Tivoli Storage Manager | 6.2.3 |
| Ibm | Tivoli Storage Manager | 6.2.4 |
| Ibm | Tivoli Storage Manager | 6.3 |
| Ibm | Tivoli Storage Manager | 6.3.0.5 |
| Ibm | Tivoli Storage Manager | 6.3.0.15 |
| Ibm | Tivoli Storage Manager | 6.3.0.17 |
| Ibm | Tivoli Storage Manager | 6.3.1 |
| Ibm | Tivoli Storage Manager | 6.3.1.2 |
| Ibm | Tivoli Storage Manager | 6.3.2.2 |
| Ibm | Tivoli Storage Manager | 6.3.3 |
| Ibm | Tivoli Storage Manager | 6.3.4 |
| Ibm | Tivoli Storage Manager | 6.3.5 |
| Ibm | Tivoli Storage Manager | 6.3.5.1 |
| Ibm | Tivoli Storage Manager | 6.3.6 |
| Ibm | Tivoli Storage Manager | 6.3.6.100 |
| Ibm | Tivoli Storage Manager | 6.4.1 |
| Ibm | Tivoli Storage Manager | 6.4.1.0 |
| Ibm | Tivoli Storage Manager | 6.4.2 |
| Ibm | Tivoli Storage Manager | 6.4.2.100 |
| Ibm | Tivoli Storage Manager | 6.4.2.200 |
| Ibm | Tivoli Storage Manager | 6.4.2.500 |
| Ibm | Tivoli Storage Manager | 6.4.2.600 |
| Ibm | Tivoli Storage Manager | 6.4.3 |
| Ibm | Tivoli Storage Manager | 6.4.3.1 |
| Ibm | Tivoli Storage Manager | 7.1 |
| Ibm | Tivoli Storage Manager | 7.1..5.100 |
| Ibm | Tivoli Storage Manager | 7.1.0.1 |
| Ibm | Tivoli Storage Manager | 7.1.0.2 |
| Ibm | Tivoli Storage Manager | 7.1.0.3 |
| Ibm | Tivoli Storage Manager | 7.1.1 |
| Ibm | Tivoli Storage Manager | 7.1.1.1 |
| Ibm | Tivoli Storage Manager | 7.1.1.2 |
| Ibm | Tivoli Storage Manager | 7.1.1.100 |
| Ibm | Tivoli Storage Manager | 7.1.1.200 |
| Ibm | Tivoli Storage Manager | 7.1.1.300 |
| Ibm | Tivoli Storage Manager | 7.1.3 |
| Ibm | Tivoli Storage Manager | 7.1.3.000 |
Showing 50 of 62 affected configurations. See NVD for the full list.
References
- http://www.ibm.com/support/docview.wss?uid=swg22006215Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/126875VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22006215Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/126875VDB Entry, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1378?
How severe is CVE-2017-1378?
How do I fix CVE-2017-1378?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-13774Hikvision iVMS-4200 devices before v2.6.2.7 allow local user…
- CVE-2017-13775GraphicsMagick 1.3.26 has a denial of service issue in ReadJ…
- CVE-2017-13776GraphicsMagick 1.3.26 has a denial of service issue in ReadX…
- CVE-2017-13777GraphicsMagick 1.3.26 has a denial of service issue in ReadX…
- CVE-2017-13778Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.p…
- CVE-2017-13779GSTN_offline_tool in India Goods and Services Tax Network (G…7.8
- CVE-2017-13780The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows di…
- CVE-2017-13782An issue was discovered in certain Apple products. macOS bef…
- CVE-2017-13783An issue was discovered in certain Apple products. iOS befor…
- CVE-2017-13784An issue was discovered in certain Apple products. iOS befor…
- CVE-2017-13785An issue was discovered in certain Apple products. iOS befor…
- CVE-2017-13786An issue was discovered in certain Apple products. macOS bef…
Are you affected by CVE-2017-1378?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
