CVE-2018-1447: High severity ibm storage protect for space management vulnerability
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-1447.
What is the severity of CVE-2018-1447?
The severity of CVE-2018-1447 is high with a severity value of 8.1.
Which software products are affected by CVE-2018-1447?
The affected software products are IBM Spectrum Protect 7.1 and 7.2, IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6, IBM Spectrum Protect For Space Management (versions between 7.1.0.0 and 7.1.8.1), IBM Spectrum Protect For Space Management (versions between 8.1.0.0 and 8.1.4.0), IBM Spectrum Protect For Virtual Environments (versions between 7.1.0.0 and 7.1.8.0), IBM Spectrum Protect For Virtual Environments (versions between 8.1.0.0 and 8.1.4.0), and IBM Spectrum Protect Snapshot (versions between 4.1.0.0 and 4.1.6.3).
What is the impact of CVE-2018-1447?
The impact of CVE-2018-1447 is that the GSKit logic fails to salt the hash function, resulting in weaker than expected protection of passwords. A weak password may be recovered.
How can I mitigate CVE-2018-1447?
To mitigate CVE-2018-1447, update the affected software products to the recommended versions and then change the passwords.