CVE-2018-1447
low-risk
Published 2018-04-04
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.
Do I need to act?
-
0.08% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.1/10
Medium
LOCAL
/ HIGH complexity
Affected Products (3)
Spectrum Protect For Space Management
Spectrum Protect For Virtual Environments
Spectrum Protect Snapshot
Affected Vendors
References (14)
22
/ 100
low-risk
Severity
13/34 · Low
Exploitability
0/34 · Minimal
Exposure
9/34 · Low