IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim account and executing a PowerShell script.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21981692 | vendor advisory |
http://www.securityfocus.com/bid/91751 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1IT12006 | vendor advisory |