First published: Wed Jun 07 2017(Updated: )
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Privileged Identity Manager | =2.0.2 | |
IBM Security Privileged Identity Manager | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5960 is classified as a high severity vulnerability due to the exposure of user credentials in plain text.
To mitigate CVE-2016-5960, it is recommended to upgrade IBM Security Privileged Identity Manager to a patched version that does not store credentials in clear text.
CVE-2016-5960 affects IBM Security Privileged Identity Manager versions 2.0.2 and 2.1.0.
CVE-2016-5960 can lead to unauthorized access to sensitive user credentials by local users.
There is no public information suggesting that CVE-2016-5960 is currently being actively exploited, but it poses a significant risk if left unaddressed.