IBM Tivoli Business Service Manager Password Disclosure Vulnerability
BID:27388
Info
IBM Tivoli Business Service Manager Password Disclosure Vulnerability
| Bugtraq ID: | 27388 |
| Class: | Design Error |
| CVE: |
CVE-2008-0441 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 22 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM Tivoli Business Service Manager 4.1.1 |
| Not Vulnerable: | |
Discussion
IBM Tivoli Business Service Manager Password Disclosure Vulnerability
IBM Tivoli Business Service Manager is prone to a local password-disclosure vulnerability due to a design error.
Exploiting this issue may allow a local attacker to access certain unencrypted passwords, potentially allowing them to access the application in an unauthorized manner. This may aid in further attacks.
This issue affects IBM Tivoli Business Service Manager 4.1.1.
IBM Tivoli Business Service Manager is prone to a local password-disclosure vulnerability due to a design error.
Exploiting this issue may allow a local attacker to access certain unencrypted passwords, potentially allowing them to access the application in an unauthorized manner. This may aid in further attacks.
This issue affects IBM Tivoli Business Service Manager 4.1.1.
Exploit / POC
IBM Tivoli Business Service Manager Password Disclosure Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
IBM Tivoli Business Service Manager Password Disclosure Vulnerability
Solution:
IBM has released fixes to address this issue. Please see the vendor reference for more information.
Solution:
IBM has released fixes to address this issue. Please see the vendor reference for more information.
References
IBM Tivoli Business Service Manager Password Disclosure Vulnerability
References:
References: