Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1447

Опубликовано: 04 апр. 2018
Источник: nvd
CVSS3: 5.1
CVSS3: 8.1
CVSS2: 5
EPSS Низкий

Описание

The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:spectrum_protect_for_space_management:*:*:*:*:*:vmware:*:*
Версия от 7.1.0.0 (включая) до 7.1.8.1 (включая)
cpe:2.3:a:ibm:spectrum_protect_for_space_management:*:*:*:*:*:vmware:*:*
Версия от 8.1.0.0 (включая) до 8.1.4.0 (включая)
cpe:2.3:a:ibm:spectrum_protect_for_virtual_environments:*:*:*:*:*:vmware:*:*
Версия от 7.1.0.0 (включая) до 7.1.8.0 (включая)
cpe:2.3:a:ibm:spectrum_protect_for_virtual_environments:*:*:*:*:*:vmware:*:*
Версия от 8.1.0.0 (включая) до 8.1.4.0 (включая)
Конфигурация 2
cpe:2.3:a:ibm:spectrum_protect_snapshot:*:*:*:*:*:vmware:*:*
Версия от 4.1.0.0 (включая) до 4.1.6.3 (включая)

EPSS

Процентиль: 24%
0.00081
Низкий

5.1 Medium

CVSS3

8.1 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-916

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.

EPSS

Процентиль: 24%
0.00081
Низкий

5.1 Medium

CVSS3

8.1 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-916