First published: Fri Apr 27 2018(Updated: )
IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Endpoint Manager | =9.0.0 | |
IBM Endpoint Manager | =9.0.1 | |
IBM Tivoli Remote Control | =5.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5461 has a high severity rating as it involves insecure storage of password hashes, making them susceptible to decryption by remote attackers.
To fix CVE-2013-5461, upgrade to the latest versions of IBM Endpoint Manager for Remote Control and Tivoli Remote Control that do not store partial password hashes.
CVE-2013-5461 affects IBM Endpoint Manager for Remote Control versions 9.0.0 and 9.0.1, as well as Tivoli Remote Control version 5.1.2.
The risks associated with CVE-2013-5461 include unauthorized access to sensitive information due to compromised password hashes.
Mitigation options for CVE-2013-5461 may include implementing additional security measures such as strong access controls and monitoring, although upgrading is strongly recommended.