The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21990215 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI61540 | vendor advisory broken link |
http://www.securityfocus.com/bid/93145 | vdb entry |