CVE-2012-3310: Low severity ibm tivoli federated identity manager business gateway vulnerability
IBM Tivoli Federated Identity Manager (TFIM) before 6.1.1.14, 6.2.0 before 6.2.0.12, and 6.2.1 before 6.2.1.4 allows context-dependent attackers to discover (1) a cleartext LDAP Bind Password, (2) keystore passwords, (3) a cleartext Basic Authentication password from a client, or (4) a cleartext user password by leveraging a logging configuration with a log trace setting of all.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3310?
CVE-2012-3310 has a medium severity rating due to the potential exposure of sensitive authentication information.
How do I fix CVE-2012-3310?
To fix CVE-2012-3310, upgrade IBM Tivoli Federated Identity Manager to versions 6.1.1.14, 6.2.0.12, or 6.2.1.4 or later.
What types of sensitive information are exposed by CVE-2012-3310?
CVE-2012-3310 can expose cleartext LDAP Bind passwords, keystore passwords, and Basic Authentication passwords.
Who is affected by CVE-2012-3310?
IBM Tivoli Federated Identity Manager users running versions prior to 6.1.1.14, 6.2.0.12, or 6.2.1.4 are affected by CVE-2012-3310.
Is CVE-2012-3310 a remote vulnerability?
CVE-2012-3310 is considered a context-dependent vulnerability, which means it requires a specific context for exploitation.