CVE-2018-1447
Last modified
CVE-2018-1447 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.
Metrics
CVSS:3.0/A:N/AC:H/AV:L/C:H/I:N/PR:N/S:U/UI:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Spectrum Protect For Space Management | >= 7.1.0.0, <= 7.1.8.1 |
| Ibm | Spectrum Protect For Space Management | >= 8.1.0.0, <= 8.1.4.0 |
| Ibm | Spectrum Protect For Virtual Environments | >= 7.1.0.0, <= 7.1.8.0 |
| Ibm | Spectrum Protect For Virtual Environments | >= 8.1.0.0, <= 8.1.4.0 |
| Ibm | Spectrum Protect Snapshot | >= 4.1.0.0, <= 4.1.6.3 |
References
- http://www.ibm.com/support/docview.wss?uid=swg22014669Patch, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22014957Patch, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22015066Patch, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22015071Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/139972VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22014669Patch, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22014957Patch, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22015066Patch, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22015071Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/139972VDB Entry, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1447?
How severe is CVE-2018-1447?
How do I fix CVE-2018-1447?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-14464The LMP parser in tcpdump before 4.9.3 has a buffer over-rea…7.5
- CVE-2018-14465The RSVP parser in tcpdump before 4.9.3 has a buffer over-re…7.5
- CVE-2018-14466The Rx parser in tcpdump before 4.9.3 has a buffer over-read…7.5
- CVE-2018-14467The BGP parser in tcpdump before 4.9.3 has a buffer over-rea…7.5
- CVE-2018-14468The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-…7.5
- CVE-2018-14469The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-r…7.5
- CVE-2018-14470The Babel parser in tcpdump before 4.9.3 has a buffer over-r…7.5
- CVE-2018-14471dwg_obj_block_control_get_block_headers in dwg_api.c in GNU …
- CVE-2018-14472An issue was discovered in WUZHI CMS 4.1.0. The vulnerable f…
- CVE-2018-14473OCS Inventory 2.4.1 lacks a proper XML parsing configuration…
- CVE-2018-14474views/auth.go in Orange Forum 1.4.0 allows Open Redirection …
- CVE-2018-14476GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter du…6.1
Are you affected by CVE-2018-1447?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
