V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2018-1447
CVE
High

The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the ha…

CVSS
8.1
High
EPSS
0.01
p55
Published
2018-01-01
Updated
2018-01-01
Description

The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.

Tags · CWE
Pre-auth
CWE-916
CAPEC-55
Affected products
Spectrum_protect_for_space_management 7.1.0.0–7.1.8.1Spectrum_protect_for_space_management 8.1.0.0–8.1.4.0Spectrum_protect_for_virtual_environments 7.1.0.0–7.1.8.0Spectrum_protect_for_virtual_environments 8.1.0.0–8.1.4.0
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.009 · p55
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-55 · CWE-916
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
spectrum_protect_for_space_management*Tracked
spectrum_protect_for_virtual_environments*Tracked
spectrum_protect_snapshot*Tracked
Source databases
CVE