CVE-2018-1447

Description

The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.081

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in IBM HTTP 9.0.0.5Windows
Multiple vulnerabilities are fixed in IBM HTTP 9.0.0.8Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.5.5.14Windows
Multiple vulnerabilities are fixed in IBM HTTP 7.0.0.45Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.15Windows
Multiple vulnerabilities are fixed in IBM WebSphere 9.0.0.9Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0.12.0Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0.0Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.2.3Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.3.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.3.1Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0.1Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0.2Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0.3Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0.4Windows
Multiple Vulnerabilities are affected in IBM MQ 9.0.4Windows
Multiple Vulnerabilities are affected in IBM Personal Communications 12.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234