CVE-2018-1447

UnknownEPSS 0.93%

Last modified

CVE-2018-1447 is a vulnerability of currently unknown severity. The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. EPSS estimates a 0.93% chance of exploitation in the next 30 days.

Description

The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.

Metrics

EPSS Probability
0.93%

56.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IbmSpectrum Protect For Space Management>= 7.1.0.0, <= 7.1.8.1
IbmSpectrum Protect For Space Management>= 8.1.0.0, <= 8.1.4.0
IbmSpectrum Protect For Virtual Environments>= 7.1.0.0, <= 7.1.8.0
IbmSpectrum Protect For Virtual Environments>= 8.1.0.0, <= 8.1.4.0
IbmSpectrum Protect Snapshot>= 4.1.0.0, <= 4.1.6.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-1447?
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.
How severe is CVE-2018-1447?
Severity scoring for CVE-2018-1447 is pending analysis. The EPSS model estimates a 0.93% probability of exploitation in the next 30 days.
How do I fix CVE-2018-1447?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-1447?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST