Hard-Coded Credentials Issue in IBM Security Identity Governance and Intelligence
CVE-2018-1944

5.1MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
21 February 2019

Summary

The IBM Security Identity Governance and Intelligence versions 5.2 through 5.2.4.1 Virtual Appliance contain hard-coded credentials, including passwords or cryptographic keys. These credentials are utilized for internal authentication processes, external communication, and encryption of sensitive data. This oversight can lead to unauthorized access and compromise of data integrity, highlighting the importance of secure credential management.

Affected Version(s)

Security Identity Governance and Intelligence 5.2

Security Identity Governance and Intelligence 5.2.1

Security Identity Governance and Intelligence 5.2.2

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.