First published: Fri Aug 02 2019(Updated: )
IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed in plain text in the ERP trace file. IBM X-Force ID: 154280.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data Protection | >=7.1.3.0<=7.1.3.1 | |
IBM Data Protection | >=7.1.3.0<=7.1.3.1 | |
IBM Data Protection | >=7.1.3.0<=7.1.3.1 | |
IBM Data Protection | >=8.1.0.0<=8.1.4.0 | |
IBM Data Protection | >=8.1.0.0<=8.1.4.0 | |
IBM Data Protection | >=8.1.0.0<=8.1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1987 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
To mitigate CVE-2018-1987, ensure tracing is not activated in IBM Spectrum Protect for Enterprise Resource Planning.
CVE-2018-1987 affects IBM Spectrum Protect for versions 7.1 up to 7.1.3.1 and 8.1 up to 8.1.6.0.
CVE-2018-1987 exposes the IBM Spectrum Protect node password in plain text within the ERP trace file.
As of now, there is no public information indicating that CVE-2018-1987 is being actively exploited.