The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/96090 | vdb entry third party advisory |
http://www.ibm.com/support/docview.wss?uid=swg21993722 | patch vendor advisory |
http://www.securitytracker.com/id/1037792 | vdb entry third party advisory |