Password Field Vulnerability in IBM InfoSphere Information Server and Business Glossary
CVE-2012-4832

Currently unrated

What is CVE-2012-4832?

The Information Services Framework (ISF) in certain versions of IBM InfoSphere Information Server and InfoSphere Business Glossary contains a flaw where the password field on the login page lacks the 'autocomplete' attribute set to 'off'. This oversight can allow attackers to retrieve user passwords from unattended workstations, posing a significant security risk to sensitive information and access control.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.