Cleartext Password Exposure in IBM Tivoli Storage Solutions
CVE-2015-7404
Currently unrated
Key Information:
- Vendor
- IBM
- Status
- Vendor
- CVE Published:
- 14 November 2015
Summary
IBM Tivoli Storage Manager for Databases, Tivoli Storage Manager for Mail, and Tivoli Storage FlashCopy Manager for Windows have a vulnerability that allows cleartext passwords to be written to application trace logs during the execution of the changetsmpassword command. This misconfiguration enables local users to access sensitive credentials through the application trace output, posing a significant security risk to affected products.
References
Timeline
Vulnerability published
Vulnerability Reserved