First published: Mon Mar 26 2018(Updated: )
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107862.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Capacity Management Analytics | =2.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7433 is considered a medium severity vulnerability due to the exposure of sensitive information.
To mitigate CVE-2015-7433, restrict access to the IBM Capacity Management Analytics installation machine.
CVE-2015-7433 exposes cleartext usernames and passwords to local users.
CVE-2015-7433 affects users of IBM Capacity Management Analytics version 2.1.0.0.
CVE-2015-7433 requires local access for exploitation, thus remote attackers cannot directly exploit it.