First published: Thu Sep 21 2017(Updated: )
IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager | =6.0 | |
IBM Security Identity Manager | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-1362 is considered high due to the exposure of user credentials in plain text.
To fix CVE-2017-1362, upgrade to a version of IBM Security Identity Manager that addresses this vulnerability.
CVE-2017-1362 affects IBM Security Identity Manager versions 6.0 and 7.0.
The implications of CVE-2017-1362 include unauthorized access to user credentials by local users.
CVE-2017-1362 cannot be exploited remotely as it requires local access to the affected system.