CVE-2016-5960: Infoleak
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5960?
CVE-2016-5960 is classified as a high severity vulnerability due to the exposure of user credentials in plain text.
How do I fix CVE-2016-5960?
To mitigate CVE-2016-5960, it is recommended to upgrade IBM Security Privileged Identity Manager to a patched version that does not store credentials in clear text.
Which versions are affected by CVE-2016-5960?
CVE-2016-5960 affects IBM Security Privileged Identity Manager versions 2.0.2 and 2.1.0.
What impact does CVE-2016-5960 have on security?
CVE-2016-5960 can lead to unauthorized access to sensitive user credentials by local users.
Is CVE-2016-5960 being actively exploited?
There is no public information suggesting that CVE-2016-5960 is currently being actively exploited, but it poses a significant risk if left unaddressed.