Lucene search

K
cveIbmCVE-2018-1987
HistoryAug 02, 2019 - 2:15 p.m.

CVE-2018-1987

2019-08-0214:15:13
CWE-287
ibm
web.nvd.nist.gov
34
ibm
spectrum protect
enterprise resource planning
security
password
tracing
vulnerability
nvd
cve-2018-1987

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

12.6%

IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed in plain text in the ERP trace file. IBM X-Force ID: 154280.

Affected configurations

Nvd
Vulners
Node
ibmdata_protectionRange7.1.3.07.1.3.1sap_for_db2
OR
ibmdata_protectionRange7.1.3.07.1.3.1sap_for_oracle
OR
ibmdata_protectionRange7.1.3.07.1.3.1sap_hana
OR
ibmdata_protectionRange8.1.0.08.1.4.0sap_for_db2
OR
ibmdata_protectionRange8.1.0.08.1.4.0sap_for_oracle
OR
ibmdata_protectionRange8.1.0.08.1.6.0sap_hana
VendorProductVersionCPE
ibmdata_protection*cpe:2.3:a:ibm:data_protection:*:*:*:*:*:sap_for_db2:*:*
ibmdata_protection*cpe:2.3:a:ibm:data_protection:*:*:*:*:*:sap_for_oracle:*:*
ibmdata_protection*cpe:2.3:a:ibm:data_protection:*:*:*:*:*:sap_hana:*:*

CNA Affected

[
  {
    "product": "Spectrum Protect for Enterprise Resource Planning",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "7.1"
      },
      {
        "status": "affected",
        "version": "8.1"
      }
    ]
  }
]

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2018-1987