CVE-2017-1339: Weak Encryption
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum protect client or administrator password which can result in information disclosure or a denial of service. IBM X-Force ID: 126247.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1339?
CVE-2017-1339 has a severity rating of medium due to the potential for information disclosure and denial of service.
How do I fix CVE-2017-1339?
To mitigate CVE-2017-1339, upgrade to a version of IBM Spectrum Protect that implements stronger encryption for passwords.
What versions of IBM Spectrum Protect are affected by CVE-2017-1339?
CVE-2017-1339 affects IBM Spectrum Protect versions 7.1 and 8.1, as well as earlier versions including 6.x.
What are the potential impacts of CVE-2017-1339?
The potential impacts of CVE-2017-1339 include unauthorized decryption of passwords leading to information disclosure and possible denial of service.
Who can exploit CVE-2017-1339?
A database administrator with access to the affected system may exploit CVE-2017-1339 to decrypt passwords easily.