Cleartext Password Storage Vulnerability in IBM Infosphere BigInsights
CVE-2015-4940

Currently unrated

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
8 November 2015

Summary

A security flaw in Apache Ambari prior to version 2.1, utilized in IBM Infosphere BigInsights 4.x before version 4.1, results in the storage of user passwords in cleartext format within a configuration file. This vulnerability permits local users to access sensitive information by simply reading the configuration file, thus exposing user credentials and potentially compromising system security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.