PT-2015-4127 · Ibm · Ibm Security Identity Manager Active Directory Adapter+1
Publicado
2015-03-25
·
Atualizado
2016-08-31
·
CVE-2014-8923
CVSS v2.0
1.9
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Identity Manager Active Directory adapter versions prior to 5.1.24
IBM Security Identity Manager Active Directory adapter versions prior to 6.0.14
Description
The issue allows local users to obtain sensitive information by reading a log file when certain log and trace levels are configured. This is because the cleartext administrator password is stored in a log file.
Recommendations
For IBM Tivoli Identity Manager Active Directory adapter versions prior to 5.1.24, update to version 5.1.24 or later.
For IBM Security Identity Manager Active Directory adapter versions prior to 6.0.14, update to version 6.0.14 or later.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Security Identity Manager Active Directory Adapter
Ibm Tivoli Identity Manager Active Directory Adapter