First published: Thu Oct 10 2019(Updated: )
IBM FileNet Content Manager in specific configurations, could log the web service user credentials into a log file that could be accessed by an administrator on the local machine.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM FileNet Content Manager | =5.5.2 | |
IBM FileNet Content Manager | =5.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2019-4572.
CVE-2019-4572 has a severity rating of 4.4, which is considered medium.
IBM FileNet Content Manager versions 5.5.2 and 5.5.3 are affected by CVE-2019-4572.
The log file containing the web service user credentials can be accessed by an administrator on the local machine.
More information about CVE-2019-4572 can be found at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/166798), [Reference 2](https://www.ibm.com/support/pages/node/1072042).