The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus Notes client and separately, might allow local users to obtain sensitive information by leveraging the persistence of cleartext password strings within process memory.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21635218 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/82656 | vdb entry |