4.7

CVE-2018-1882

In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Spectrum Protect Backup-archive Client Version >= 7.1.0.0 <= 7.1.8.4
   Apple ≫ macOS Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Ibm ≫ Spectrum Protect Backup-archive Client Version >= 8.1.0.0 <= 8.1.6.1
   Apple ≫ macOS Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Ibm ≫ Spectrum Protect For Virtual Environments SwPlatform vmware Version >= 7.1.0.0 <= 7.1.8.4
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Ibm ≫ Spectrum Protect For Virtual Environments SwPlatform vmware Version >= 8.1.0.0 <= 8.1.6.1
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Ibm ≫ Spectrum Protect For Virtual Environments SwPlatform hyper-v Version >= 7.1.0.0 <= 7.1.8.0
   Microsoft ≫ Windows Version -
Ibm ≫ Spectrum Protect For Virtual Environments SwPlatform hyper-v Version >= 8.1.0.0 <= 8.1.6.1
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.13
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:P/I:N/A:N
IBM 4.7 1 3.6
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

http://www.ibm.com/support/docview.wss?uid=ibm10869208
Patch
Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=ibm10869436
Patch
Vendor Advisory
http://www.securityfocus.com/bid/107861
Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/151968
Vendor Advisory
VDB Entry