CVE-2015-1934: Medium severity ibm tivoli change and configuration management database vulnerability
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly encrypt passwords, which makes it easier for context-dependent attackers to determine cleartext passwords by leveraging access to a password file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1934?
CVE-2015-1934 has been assigned a severity rating of moderate, indicating potential threats that could impact the affected systems.
How do I fix CVE-2015-1934?
To fix CVE-2015-1934, it is recommended to upgrade IBM Maximo Asset Management and associated software to the latest available versions that address the vulnerability.
What versions are affected by CVE-2015-1934?
CVE-2015-1934 affects IBM Maximo Asset Management versions 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001, among others.
What types of systems are impacted by CVE-2015-1934?
CVE-2015-1934 impacts systems running IBM Maximo Asset Management, IBM SmartCloud Control Desk, and Tivoli IT Asset Management software.
Is CVE-2015-1934 exploitable remotely?
Yes, CVE-2015-1934 can potentially be exploited remotely, making it important for users to apply mitigations promptly.