CVE-2017-1378: High severity ibm tivoli storage manager vulnerability
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1378?
CVE-2017-1378 has been classified as a medium severity vulnerability due to the exposure of unencrypted login credentials.
How do I fix CVE-2017-1378?
Fix CVE-2017-1378 by upgrading to a patched version of IBM Spectrum Protect, which addresses the issue of credential exposure.
Which versions of IBM Spectrum Protect are affected by CVE-2017-1378?
CVE-2017-1378 affects IBM Spectrum Protect versions 7.1 and 8.1, specifically including multiple listed minor releases.
What type of data is exposed due to CVE-2017-1378?
CVE-2017-1378 exposes unencrypted login credentials for VMware vCenter in the application trace output.
Who can exploit the vulnerability CVE-2017-1378?
The vulnerability CVE-2017-1378 can be exploited by any local user who has access to the application trace output.