Weak Password Protection in IBM Spectrum Protect and Snapshot Products
CVE-2018-1447

5.1MEDIUM

Summary

The GSKit component in specific versions of IBM Spectrum Protect and IBM Spectrum Protect Snapshot has a vulnerability wherein the KDB logic fails to properly salt the hash function. This oversight results in a weakened password protection mechanism, allowing for the potential recovery of weak passwords. It is critical for users of these affected products to change their passwords following an update to ensure enhanced security, as the vulnerability underscores the importance of robust hashing processes to safeguard sensitive information.

Affected Version(s)

Spectrum Protect 7.1

Spectrum Protect 8.1

Spectrum Protect for Space Management 7.1

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.