IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 logs cleartext passwords, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/92073 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI13527 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21669506 | vendor advisory |