PT-2024-9573 · Ibm · Ibm Workload Scheduler

Alberto Arganese

+3

·

Published

2024-11-25

·

Updated

2024-11-26

·

CVE-2024-49351

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Workload Scheduler versions 9.5 through 10.2
Description The issue is related to the storage of passwords in plain text. This could allow an attacker to disclose protected information. A local user can read the user credentials stored in plain text.
Recommendations For versions 9.5 through 10.2, update to a version that stores user credentials securely, avoiding plain text storage. As a temporary workaround, consider restricting access to the areas where credentials are stored to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-11280
CVE-2024-49351

Affected Products

Ibm Workload Scheduler