IBM Event Pump for z/OS Password Information Disclosure Vulnerability
BID:52883
Info
IBM Event Pump for z/OS Password Information Disclosure Vulnerability
| Bugtraq ID: | 52883 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 04 2012 12:00AM |
| Updated: | Apr 04 2012 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
IBM Tivoli Event Pump for z/OS 4.2.2 |
| Not Vulnerable: | |
Discussion
IBM Event Pump for z/OS Password Information Disclosure Vulnerability
IBM Event Pump for z/OS is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
IBM Event Pump for z/OS version 4.2.2 is vulnerable.
IBM Event Pump for z/OS is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
IBM Event Pump for z/OS version 4.2.2 is vulnerable.
Exploit / POC
IBM Event Pump for z/OS Password Information Disclosure Vulnerability
Attackers can exploit the issue using standard commands.
Attackers can exploit the issue using standard commands.
Solution / Fix
IBM Event Pump for z/OS Password Information Disclosure Vulnerability
Solution:
Updates are available for this issue. Please see the references for details.
Solution:
Updates are available for this issue. Please see the references for details.
References
IBM Event Pump for z/OS Password Information Disclosure Vulnerability
References:
References: