CVE-2018-1785: Weak Encryption
Published Sep 26, 2018
·Updated
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.
Affected Software
8 affected components
IBM Spectrum Protect Client>=7.1.0.0<=7.1.8.3
IBM Spectrum Protect Client>=8.1.0.0<=8.1.4.1
IBM Spectrum Protect For Virtual Environments Hyper-v>=7.1.0.0<=7.1.8.0
IBM Spectrum Protect For Virtual Environments Vmware>=7.1.0.0<=7.1.8.2
IBM Spectrum Protect For Virtual Environments Hyper-v>=8.1.0.0<=8.1.4.0
IBM Spectrum Protect For Virtual Environments Vmware>=8.1.0.0<=8.1.4.1
IBM Spectrum Protect Client>=8.1.0.0<=8.1.4.2
Apple macOS
Event History
Sep 26, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-1785.
2
What is the severity of CVE-2018-1785?
The severity of CVE-2018-1785 is high with a severity score of 7.5.
3
What is affected by CVE-2018-1785?
IBM Tivoli Storage Manager (IBM Spectrum Protect) versions 7.1 and 8.1 are affected by CVE-2018-1785.
4
What is the impact of CVE-2018-1785?
CVE-2018-1785 could allow an attacker to decrypt sensitive information.
5
How can I fix CVE-2018-1785?
To fix CVE-2018-1785, update to a version of IBM Tivoli Storage Manager (IBM Spectrum Protect) that uses stronger cryptographic algorithms, as recommended by IBM.