PT-2018-4125 · Ibm · Ibm Security Key Lifecycle Manager
Published
2018-04-25
·
Updated
2018-06-13
·
CVE-2014-0872
CVSS v2.0
1.5
Low
| Vector | AV:L/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Key Lifecycle Manager version 2.5
Description
The installation process stores unencrypted credentials, potentially allowing local users with root access to obtain sensitive information.
Recommendations
For IBM Security Key Lifecycle Manager version 2.5, consider restricting root access to minimize the risk of exploitation until a fix is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Security Key Lifecycle Manager