PT-2008-2073 · Ibm · Ibm Tivoli Business Service Manager

Published

2008-01-24

·

Updated

2017-08-08

·

CVE-2008-0441

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Business Service Manager (TBSM) version 4.1.1
Description The issue allows local users to obtain sensitive information because passwords are stored in cleartext after external authentication and reconfig actions, which triggers writing the password to SM server.log.
Recommendations For IBM Tivoli Business Service Manager (TBSM) version 4.1.1, consider restricting access to the SM server.log file to minimize the risk of sensitive information disclosure until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-0441

Affected Products

Ibm Tivoli Business Service Manager