CVE-2018-1786
https://notcve.org/view.php?id=CVE-2018-1786
IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871. Los procesos dsmc y dsmcad de IBM Spectrum Protect 7.1 y 8.1 acumulan incorrectamente sockets TCP/IP en un estado CLOSE_WAIT. Esto puede provocar el filtrado del recurso TCP/IP y podría resultar en una denegación de servicio (DoS). • http://www.ibm.com/support/docview.wss?uid=ibm10738765 http://www.securityfocus.com/bid/105940 https://exchange.xforce.ibmcloud.com/vulnerabilities/148871 • CWE-400: Uncontrolled Resource Consumption •
CVE-2018-1785
https://notcve.org/view.php?id=CVE-2018-1785
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870. IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 y 8.1) emplea algoritmos criptográficos más débiles de lo esperado que podrían permitir que un atacante descifre información sensible. IBM X-Force ID: 148870. • http://www.ibm.com/support/docview.wss?uid=ibm10729873 http://www.securitytracker.com/id/1041716 https://exchange.xforce.ibmcloud.com/vulnerabilities/148870 • CWE-326: Inadequate Encryption Strength •
CVE-2018-1545
https://notcve.org/view.php?id=CVE-2018-1545
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649. IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 y 8.1) emplea algoritmos criptográficos más débiles de lo esperado que podrían permitir que un atacante descifre información altamente sensible. IBM X-Force ID: 142649. • http://www.ibm.com/support/docview.wss?uid=ibm10718013 https://exchange.xforce.ibmcloud.com/vulnerabilities/142649 • CWE-326: Inadequate Encryption Strength •
CVE-2018-1447
https://notcve.org/view.php?id=CVE-2018-1447
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972. • http://www.ibm.com/support/docview.wss?uid=swg22014669 http://www.ibm.com/support/docview.wss?uid=swg22014957 http://www.ibm.com/support/docview.wss?uid=swg22015066 http://www.ibm.com/support/docview.wss?uid=swg22015071 http://www.securityfocus.com/bid/104511 http://www.securitytracker.com/id/1041012 https://exchange.xforce.ibmcloud.com/vulnerabilities/139972 • CWE-916: Use of Password Hash With Insufficient Computational Effort •
CVE-2015-7426
https://notcve.org/view.php?id=CVE-2015-7426
The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors. La extensión Data Protection en la GUI VMware en IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (también conocido como Spectrum Protect for Virtual Environments) 7.1 en versiones anteriores a 7.1.3.0 y Tivoli Storage FlashCopy Manager for VMware (también conocido como Spectrum Protect Snapshot) 4.1 en versiones anteriores a 4.1.3.0 permite a atacantes remotos ejecutar comandos del SO arbitrarios a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21971484 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •