Lucene search

K
cve[email protected]CVE-2014-8923
HistoryMar 25, 2015 - 1:59 a.m.

CVE-2014-8923

2015-03-2501:59:11
CWE-200
web.nvd.nist.gov
25
ibm tivoli
ibm security identity manager
active directory
cleartext password
log file
vulnerability
nvd
cve-2014-8923

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

5.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows local users to obtain sensitive information by reading a file.

Affected configurations

NVD
Node
ibmsecurity_identity_manager_active_directory_adapterRange6.0.14windows
OR
ibmtivoli_identity_manager_active_directory_adapterRange5.1.20windows

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

5.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2014-8923