PT-2017-8888 · Ibm · Ibm Tivoli Key Lifecycle Manager

Published

2017-02-07

·

Updated

2017-02-09

·

CVE-2016-6092

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Key Lifecycle Manager versions 2.0.1, 2.5, and 2.6
Description The issue concerns the storage of user credentials in plain text, allowing a local user to read them.
Recommendations For IBM Tivoli Key Lifecycle Manager version 2.0.1, consider updating the credential storage mechanism to encrypt user credentials. For IBM Tivoli Key Lifecycle Manager version 2.5, consider updating the credential storage mechanism to encrypt user credentials. For IBM Tivoli Key Lifecycle Manager version 2.6, consider updating the credential storage mechanism to encrypt user credentials.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6092

Affected Products

Ibm Tivoli Key Lifecycle Manager