IBM Security Bulletin: Password disclosure via instrumentation log file in IBM Spectrum Protect Plus (CVE-2018-1768)

IBM Spectrum Protect Plus may display the user id and password in plain text within the instrumentation log file.

CVE(s): CVE-2018-1768

Affected product(s) and affected version(s):

IBM Spectrum Protect Plus 10.1.0 and 10.1.1.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10729219
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148622

The post IBM Security Bulletin: Password disclosure via instrumentation log file in IBM Spectrum Protect Plus (CVE-2018-1768) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2Ic6JTp