Hard-Coded Credentials Issue in IBM Security Identity Governance and Intelligence
CVE-2018-1944
5.1MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 21 February 2019
Summary
The IBM Security Identity Governance and Intelligence versions 5.2 through 5.2.4.1 Virtual Appliance contain hard-coded credentials, including passwords or cryptographic keys. These credentials are utilized for internal authentication processes, external communication, and encryption of sensitive data. This oversight can lead to unauthorized access and compromise of data integrity, highlighting the importance of secure credential management.
Affected Version(s)
Security Identity Governance and Intelligence 5.2
Security Identity Governance and Intelligence 5.2.1
Security Identity Governance and Intelligence 5.2.2
References
CVSS V3.1
Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved