Weak passwords requirements in Spectrum Protect Snapshot and Spectrum Protect Server - CVE-2018-1447

 

Weak passwords requirements in Spectrum Protect Snapshot and Spectrum Protect Server - CVE-2018-1447

Published: May 1, 2018


Vulnerability identifier: #VU12308
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1447
CWE-ID: CWE-521
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local unauthenticated attacker to obtain potentially sensitive information on the target system.

The weakness exists due to the GSKit CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. A local attacker can gain access to potentially sensitive information.

Affected software

Spectrum Protect Snapshot
IBM MQ
Spectrum Protect Server
Planning Analytics Local
IBM Cognos Analytics
Security Network Protection
IBM Tivoli Directory Server
IBM Cognos Controller
Tivoli Network Manager IP Edition

How to mitigate CVE-2018-1447

Install update from vendor's website.

IBM Cognos Analytics - update to 11.0.13
Tivoli Network Manager IP Edition - update to 4.2.0.5

External References

Related Security Bulletins