Weak Password Protection in IBM Spectrum Protect and Snapshot Products
CVE-2018-1447 
5.1MEDIUM
Key Information:
- Vendor
- IBM
- Status
- Vendor
- CVE Published:
- 4 April 2018
What is CVE-2018-1447?
The GSKit component in specific versions of IBM Spectrum Protect and IBM Spectrum Protect Snapshot has a vulnerability wherein the KDB logic fails to properly salt the hash function. This oversight results in a weakened password protection mechanism, allowing for the potential recovery of weak passwords. It is critical for users of these affected products to change their passwords following an update to ensure enhanced security, as the vulnerability underscores the importance of robust hashing processes to safeguard sensitive information.
Affected Version(s)
Spectrum Protect 7.1
Spectrum Protect 8.1
Spectrum Protect for Space Management 7.1