CVE-2018-1882: Medium severity ibm storage protect backup-archive client vulnerability
Published Apr 8, 2019
·Updated
In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
Affected Software
11 affected components
IBM Spectrum Protect Backup-Archive Client>=7.1.0.0<=7.1.8.4
IBM Spectrum Protect Backup-Archive Client>=8.1.0.0<=8.1.6.1
Apple macOS
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
IBM Spectrum Protect For Virtual Environments Vmware>=7.1.0.0<=7.1.8.4
IBM Spectrum Protect For Virtual Environments Vmware>=8.1.0.0<=8.1.6.1
IBM Spectrum Protect For Virtual Environments Hyper-v>=7.1.0.0<=7.1.8.0
IBM Spectrum Protect For Virtual Environments Hyper-v>=8.1.0.0<=8.1.6.1
Remediation
Patch Available
Patch Available
Event History
Apr 8, 2019
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1882?
The severity of CVE-2018-1882 is medium with a severity value of 4.7.
2
What software is affected by CVE-2018-1882?
IBM Spectrum Protect Backup-Archive Client versions 7.1.0.0 to 7.1.8.4 and versions 8.1.0.0 to 8.1.6.1 are affected.
3
How can the node password be displayed in plain text?
The node password can be displayed in plain text in the IBM Spectrum Protect client trace file in certain atypical configurations.
4
Is Apple macOS vulnerable to CVE-2018-1882?
No, Apple macOS is not vulnerable to CVE-2018-1882.
5
Is there a fix available for CVE-2018-1882?
Yes, IBM has provided fixes for the affected versions of IBM Spectrum Protect Backup-Archive Client.