First published: Wed Sep 26 2018(Updated: )
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect client | >=7.1.0.0<=7.1.8.3 | |
IBM Spectrum Protect client | >=8.1.0.0<=8.1.4.1 | |
Ibm Spectrum Protect For Virtual Environments | >=7.1.0.0<=7.1.8.0 | |
Ibm Spectrum Protect For Virtual Environments | >=7.1.0.0<=7.1.8.2 | |
Ibm Spectrum Protect For Virtual Environments | >=8.1.0.0<=8.1.4.0 | |
Ibm Spectrum Protect For Virtual Environments | >=8.1.0.0<=8.1.4.1 | |
IBM Spectrum Protect client | >=8.1.0.0<=8.1.4.2 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-1785.
The severity of CVE-2018-1785 is high with a severity score of 7.5.
IBM Tivoli Storage Manager (IBM Spectrum Protect) versions 7.1 and 8.1 are affected by CVE-2018-1785.
CVE-2018-1785 could allow an attacker to decrypt sensitive information.
To fix CVE-2018-1785, update to a version of IBM Tivoli Storage Manager (IBM Spectrum Protect) that uses stronger cryptographic algorithms, as recommended by IBM.