Vulnerability Description
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 137772.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Guardium Big Data Intelligence | 3.1 |
Related Weaknesses (CWE)
References
- http://www.ibm.com/support/docview.wss?uid=swg22013832Vendor Advisory
- http://www.securityfocus.com/bid/103237Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/137772VDB EntryVendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22013832Vendor Advisory
- http://www.securityfocus.com/bid/103237Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/137772VDB EntryVendor Advisory
FAQ
What is CVE-2018-1372?
CVE-2018-1372 is a vulnerability with a CVSS score of 9.8 (CRITICAL). IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-For...
How severe is CVE-2018-1372?
CVE-2018-1372 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-1372?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Security Guardium Big Data Intelligence.