Lucene search

K
ibmIBM65D1ECC08FD39D88FB4523EE69BA16CC5E59614513C98F70FC4306624777C11C
HistoryJul 26, 2018 - 9:03 p.m.

Security Bulletin: Vulnerability IBM GSKit affect IBM Host On-Demand

2018-07-2621:03:10
www.ibm.com
14

EPSS

0.005

Percentile

76.2%

Summary

GSKit is an IBM component that is used by Host On-Demand. GSKit that is shipped with Host On-Demand contains security vulnerability. Host On-Demand has addressed it.

Vulnerability Details

CVEID: CVE-2018-1447 DESCRIPTION: The GSKit CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action.
CVSS Base Score: 5.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/139972for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Host On-Demand 13.0

Host On-Demand 12.0, 12.0.0.1, 12.0.1, 12.0.2, 12.0.3

Remediation/Fixes

Product

|

VRMF

|

Remediation

โ€”|โ€”|โ€”

Host On-Demand

|

12.0

|

Upgrade to Host On-Demand 12.0.4

Host On-Demand

|

12.0.0.1

|

Upgrade to Host On-Demand 12.0.4

Host On-Demand

|

12.0.1

|

Upgrade to Host On-Demand 12.0.4

Host On-Demand

|

12.0.2

|

Upgrade to Host On-Demand 12.0.4

Host On-Demand

|

12.0.3

|

Upgrade to Host On-Demand 12.0.4

Host On-Demand

|

13.0

|

Upgrade to Host On-Demand 13.0.1

Workarounds and Mitigations

None

EPSS

0.005

Percentile

76.2%

Related for 65D1ECC08FD39D88FB4523EE69BA16CC5E59614513C98F70FC4306624777C11C