VYPR
Unrated severityNVD Advisory· Published Feb 27, 2018· Updated Sep 17, 2024

CVE-2018-1372

CVE-2018-1372

Description

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 137772.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not enforce strong passwords by default, making it easier to compromise user accounts.

Vulnerability

IBM Security Guardium Big Data Intelligence (SonarG) version 3.1 does not require that users have strong passwords by default [1]. The product ships with a weak password policy, meaning that user accounts can be created or configured without enforcing complexity or length requirements.

Exploitation

An attacker with network access to the SonarG web interface could attempt to compromise user accounts by guessing or brute-forcing weak passwords [1]. The attacker does not need prior authentication; however, successful exploitation requires the attacker to identify a user account that has a weak or default password.

Impact

Successful exploitation allows the attacker to gain unauthorized access to an affected user's account [1]. This could lead to disclosure of sensitive information processed or stored by the SonarG application, as described in the CVSS vector (confidentiality impact is High) [1].

Mitigation

IBM has not published a specific fix or patch version in the available reference [1]. The advisory states "None" under workarounds and mitigations. Users should contact IBM support for the latest remediation guidance. As a general security practice, organizations should enforce a strong password policy manually via configuration settings to mitigate this issue.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.