CVE-2014-6111: High severity ibm security identity manager vulnerability
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 store encrypted user credentials and the keystore password in cleartext in configuration files, which allows local users to decrypt SIM credentials via unspecified vectors. IBM X-Force ID: 96180.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2014-6111?
CVE-2014-6111 is a vulnerability in IBM Tivoli Identity Manager and Security Identity Manager that allows local users to decrypt encrypted user credentials and the keystore password stored in cleartext configuration files.
What software is affected by CVE-2014-6111?
IBM Tivoli Identity Manager versions 5.1.x, Security Identity Manager versions 6.0.x and 7.0.x are affected by CVE-2014-6111.
What is the severity of CVE-2014-6111?
The severity of CVE-2014-6111 is rated as high with a CVSS score of 7.8.
How can an attacker exploit CVE-2014-6111?
An attacker with local access can exploit CVE-2014-6111 by gaining access to the cleartext configuration files containing encrypted user credentials and the keystore password.
Are there any references related to CVE-2014-6111?
Yes, you can find more information about CVE-2014-6111 at the following references: [Reference 1](http://www-01.ibm.com/support/docview.wss?uid=swg21698020) and [Reference 2](https://exchange.xforce.ibmcloud.com/vulnerabilities/96180).