First published: Tue Dec 11 2018(Updated: )
IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 124743.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | >=10.0<=10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-1268 is rated as important due to the potential for password recovery and unauthorized access.
To fix CVE-2017-1268, upgrade IBM Security Guardium to version 10.5 or later, which addresses the hashing vulnerability.
CVE-2017-1268 affects IBM Security Guardium versions 10.0 to 10.5 without proper salting during password hashing.
CVE-2017-1268 is a cryptographic vulnerability related to weak password hashing without a salt.
Yes, CVE-2017-1268 can potentially be exploited remotely, allowing attackers to recover passwords.