PT-2018-4125 · Ibm · Ibm Security Key Lifecycle Manager
Publicado
2018-04-25
·
Atualizado
2018-06-13
·
CVE-2014-0872
CVSS v2.0
1.5
Baixa
| Vetor | AV:L/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Key Lifecycle Manager version 2.5
Description
The installation process stores unencrypted credentials, potentially allowing local users with root access to obtain sensitive information.
Recommendations
For IBM Security Key Lifecycle Manager version 2.5, consider restricting root access to minimize the risk of exploitation until a fix is available.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ibm Security Key Lifecycle Manager