IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg21997986 | patch vendor advisory |
http://www.securityfocus.com/bid/95977 | vdb entry third party advisory |