IBM Spectrum Protect Plus may display the user id and password in plain text within the instrumentation log file.
CVE(s): CVE-2018-1768
Affected product(s) and affected version(s):
IBM Spectrum Protect Plus 10.1.0 and 10.1.1.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10729219
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148622
The post IBM Security Bulletin: Password disclosure via instrumentation log file in IBM Spectrum Protect Plus (CVE-2018-1768) appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/2Ic6JTp
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.