The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg1IO11882 | vendor advisory |
http://www.ibm.com/support/docview.wss?uid=swg24029663 | patch |