First published: Fri Apr 20 2018(Updated: )
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 store encrypted user credentials and the keystore password in cleartext in configuration files, which allows local users to decrypt SIM credentials via unspecified vectors. IBM X-Force ID: 96180.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager | =6.0 | |
IBM Security Identity Manager | =7.0 | |
IBM Tivoli Identity Manager | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6111 is a vulnerability in IBM Tivoli Identity Manager and Security Identity Manager that allows local users to decrypt encrypted user credentials and the keystore password stored in cleartext configuration files.
IBM Tivoli Identity Manager versions 5.1.x, Security Identity Manager versions 6.0.x and 7.0.x are affected by CVE-2014-6111.
The severity of CVE-2014-6111 is rated as high with a CVSS score of 7.8.
An attacker with local access can exploit CVE-2014-6111 by gaining access to the cleartext configuration files containing encrypted user credentials and the keystore password.
Yes, you can find more information about CVE-2014-6111 at the following references: [Reference 1](http://www-01.ibm.com/support/docview.wss?uid=swg21698020) and [Reference 2](https://exchange.xforce.ibmcloud.com/vulnerabilities/96180).